Microsoft Defender XDR
Incidents and response

Alert Grading Playbook Inbox Forwarding Rules

In brief

The article now uses clearer terminology for investigating suspicious rule parameters, identifying the IP involved in inbox rule creation, and remediating account compromise. Its metadata and publication date were also updated.

What Defender admins need to know

Administrators can use the revised wording when investigating and responding to suspicious inbox forwarding rules; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate rule parameters

The purpose of this stagethe rule-parameter investigation is to determine ifwhether the rules look suspicious by certainbased on the following criteria:

Recipients of the forwarding rule:

Investigate IP address

Review the attributes that related to the IP address that performed the relevant event ofinbox rule creation:creation event:

  1. Search for other suspicious cloud activities that originated from the same IP in the tenant. For instance, suspicious activity might be multiple failed login attempts.
  2. Is the ISP common and reasonable for this user?

Recommended actions

If you confirm that the inbox forwarding rule is malicious, take the following actions to remediate the attack:account compromise:

  1. Disable the malicious inbox rule.
  2. Reset the user's account credentials. You can also verify if the user account has been compromised with Microsoft Defender for Cloud Apps, which gets security signals from Microsoft Entra ID Protection.