Microsoft Defender XDR
Incidents and response

Alert Grading Playbook Email Forwarding

In brief

The playbook now presents alert-review steps as a numbered sequence, clarifies terminology for the forwarding user and recipient lists, and refines investigation and remediation wording. Metadata and the documentation date were also updated.

What Defender admins need to know

No administrator action is required; the revised guidance may make investigating these alerts easier.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.collection:

  • m365-security
  • tier2 ms.custom: admindeeplinkDEFENDER, msecd-doc-authoring-10141016 ms.topic: how-to ms.date: 06/15/07/02/2026 appliesto:
  • Microsoft Defender XDR ai-usage: ai-assisted

Alert details for suspicious email forwarding activity

To review the Suspicious Email Forwarding Activity alert, openalert:

  1. Open the Alerts page to see the Activity list section. Here's an example.

    :::image type="content" source="media/alert-grading-playbook-email-forwarding/alert-grading-playbook-email-forwarding-activity-list.png" alt-text="List of activities related to the alert" lightbox="media/alert-grading-playbook-email-forwarding/alert-grading-playbook-email-forwarding-activity-list.png":::

  2. Select Activity to view the details of the selected alert activity in the sidebar. Here's an example.

:::image type="content" source="media/alert-grading-playbook-email-forwarding/alert-grading-playbook-email-forwarding-activity-details.png" alt-text="Details of the activity" lightbox="media/alert-grading-playbook-email-forwarding/alert-grading-playbook-email-forwarding-activity-details.png":::

Is the user account and its mailbox compromised?

By looking at senderthe forwarding user's past behavior and recent activities, you should be able to determine whether the user's account should be considered compromised or not. You can see the details of alerts raised from the user's page in the Microsoft Defender portal.

You can also analyze these other activities for the affected mailbox:

Threat Explorer provides an interactive investigation experience for email related threats to determine whether the flagged email-forwarding activity is suspicious or not. You can use the following indicators from the alert information:

  • Suspicious Recipients List (SRL) / Recipients List (RL): Use theThe alert includes an SRL or RL fromthat identifies the alertrecipients involved in the forwarding activity. Use these lists to find thesethe following details:

    :::image type="content" source="media/alert-grading-playbook-email-forwarding/alert-grading-playbook-email-forwarding-recipients-list.png" alt-text="Example of the list of recipients" lightbox="media/alert-grading-playbook-email-forwarding/alert-grading-playbook-email-forwarding-recipients-list.png":::

Investigate IP addresses and new forwarding rules

Along with the evidence gathered during thisthe suspicious email forwarding investigation, you can determine if there are new forwarding rules being created. Investigate the IP address associated with the rule. Ensure that it is not an anomalous IP address and is consistent with usual activities performed by the user.

Recommended actions

Once you determine that the associated email forwarding activities associated make this alert a True Positive, classify the alert and take these actions for remediation:

  1. Disable and delete the inbox forwarding rule.
  2. For the InboxRule forwarding type, reset the user's account credentials.