Forum Discussion
MikeP751860
Sep 27, 2023Brass Contributor
OfficeActivity - Rare and potentially high-risk Office operations and automation
Hi, We are receiving a number of "OfficeActivity - Rare and potentially high-risk Office operations" alerts for users who are setting up mailbox GrantSendOnBehaveOf and creating mail moving rules...
Tobias_Moe
Oct 26, 2023Copper Contributor
Hi, I actually have not changed this rule myself yet. But my initial thought is to look at the mailboxes being shared, and to which users. From my experience, the most common false positive for this is people sharing access to their mailbox for a short period because they are going on vacation or sick leave or something else. So I would not say it is malicious to share your inbox internally. However, if shared externally and to another domain it would be more suspicious.
Tobias_Moe
Oct 26, 2023Copper Contributor
Another point, look for newly created users as well as that could be potential internal suspicious user getting access