Microsoft Exchange Online
Nobody notices email until the hour it stops
Exchange Online delivers the mail, and Microsoft keeps the service running. What it does not do is decide who may access a mailbox, how long messages are kept, whether a departed employee's mail remains reachable, or what happens when an account is compromised. Those are configuration choices, and they are where the value of running it well actually sits.
The service is managed. Your tenant is not.
Moving mail to a cloud platform genuinely removes a great deal of work. There is no server to patch, no storage to expand at an awkward moment, and no Saturday spent recovering a database. That part of the promise is real and it was worth making the move for.
What did not transfer is the administrative responsibility. Microsoft guarantees the platform is available; it does not decide your retention policy, review who has been granted access to whose mailbox, or notice that a rule was created yesterday forwarding a finance director's mail to an outside address.
That last example is worth dwelling on, because it is the most common indicator of a compromised mailbox and one of the least frequently monitored. An attacker who obtains credentials usually does not announce themselves. They read quietly, and they set up a way to keep reading.
What a compromised mailbox actually looks like
The sequence is consistent enough to be worth knowing, because every stage after the first is detectable if somebody is looking.
The decisions that belong to you
- Retention and litigation hold
- How long mail is kept, and whether it can be preserved beyond that when a legal matter requires it. Retention is a deliberate choice in both directions, since keeping everything indefinitely creates discovery and breach exposure as well as removing risk.
- Mailbox permissions
- Who has been granted access to whose mailbox, and whether those grants are still appropriate. Delegated access accumulates through maternity cover, holidays and role changes, and is very rarely reviewed afterwards.
- Forwarding rules
- Whether automatic forwarding to external addresses is permitted at all, and whether anybody is alerted when a new rule appears. This single control catches a large share of business email compromise.
- Shared and departed mailboxes
- What happens to a leaver's mail. Converting to a shared mailbox retains the content without consuming a licence, which is both cheaper and considerably safer than the common alternative of leaving the account active.
Questions a well run tenant can answer
| Question | Typical answer | Well administered |
|---|---|---|
| Who can read the director's mailbox | Unclear | A reviewed list |
| Is mail forwarded outside the organization | Unknown | Blocked or alerted |
| How long is mail retained | Forever, by default | A deliberate period |
| Can we recover a deleted mailbox | Within a short window | From a separate backup |
| Would we notice a compromise | Probably not | Rules and sign-ins monitored |
What ongoing administration looks like
None of this is a project with an end date. Permissions accumulate continuously, staff join and leave, new forwarding rules appear, and licence assignments drift away from the actual headcount. A tenant reviewed once is accurate for about a quarter.
The practical arrangement most organizations need is a regular review of the small number of things that genuinely change risk: delegated mailbox access, external forwarding, dormant accounts still licensed, and whether the alerting that exists is actually being read by somebody.
Check for forwarding rules this week
It takes very little time, it is the single highest value check available in a mail tenant, and finding one you did not expect changes the conversation entirely.
Book the mailbox reviewGet in touch with Your Company
Questions about this solution? Reach us directly.