SOLVED
Home

Secure Score - New Client External Rules Forwarding Block control

%3CLINGO-SUB%20id%3D%22lingo-sub-92021%22%20slang%3D%22en-US%22%3ESecure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-92021%22%20slang%3D%22en-US%22%3E%3CP%3ESecure%20Score%20can%20now%20help%20stop%20data%20exfiltration%20with%20client%20created%20rules%2C%20that%20auto-forwards%20email%20from%20users%20mailboxes%20to%20an%20external%20email%20address.%20%26nbsp%3BThis%20is%20apparently%20an%20increasingly%20common%20data%20leakage%26nbsp%3Bmethod%20that%20is%20being%20successfully%20used%20by%20'bad%20actors'.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESecure%20Score%20has%20a%20new%20security%20control%20called%26nbsp%3B'Client%20Rules%20Forwarding%20Blocks'%20that%20implements%20a%20Transport%20Rule%20to%20help%20mitigate%20client%20created%20rules%20that%20Auto-Forward%20to%20external%20addresses.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F18015iA0DD8C8D42AFC20D%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22Secure%20Score%20Client%20Rules%20Forwarding%20Block.png%22%20title%3D%22Secure%20Score%20Client%20Rules%20Forwarding%20Block.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20enabled%2C%20this%20will%20apply%20the%20following%20logic%20via%20a%20transport%20rule%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%3EIF%20The%20Sender%20is%20located%20%E2%80%98Inside%20the%20organization%E2%80%99%20%3CBR%20%2F%3EAND%20IF%20The%20Recipient%20is%20located%20%E2%80%98Outside%20the%20organization%E2%80%99%20%3CBR%20%2F%3EAND%20IF%20The%20message%20type%20is%20%E2%80%98Auto-Forward%E2%80%99%20%3CBR%20%2F%3ETHEN%20Reject%20the%20message%20with%20the%20explanation%20%E2%80%98External%20Email%20Forwarding%20via%20Client%20Rules%20is%20not%20permitted%E2%80%99.%3C%2FPRE%3E%3CP%3E%3CSPAN%3EThis%20feature%20is%20now%20live%20within%20Secure%20Score.%20%26nbsp%3B%3C%2FSPAN%3ESee%20the%20announcement%20here%20for%20further%20details%20-%20%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Foffice365security%2Fmitigating-client-external-forwarding-rules-with-secure-score%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EMitigating%20Client%20External%20Forwarding%20Rules%20with%20Secure%20Score%3C%2FA%3E.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CEM%3EPerhaps%26nbsp%3Bthese%20sorts%20of%20announcements%26nbsp%3Bcould%20be%20posted%20to%20this%20community%20blog%20in%20the%20future%20like%20there%20have%20been%20for%20previous%20Secure%20Score%20new%20features%3F%26nbsp%3B%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-92021%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-389550%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389550%22%20slang%3D%22en-US%22%3E%3CP%3EDoes%20this%20apply%20to%20Microsoft%20Flows%20that%20auto-forward%20email%3F%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F2395%22%20target%3D%22_blank%22%3E%40Cian%20Allner%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-279106%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-279106%22%20slang%3D%22en-US%22%3EAny%20luck%20getting%20this%20to%20work%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-203762%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-203762%22%20slang%3D%22en-US%22%3E%3CP%3EHi.%20Any%20updates%20on%20this%3F%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20not%20able%20to%20add%20an%20exception%20either.%20It%20doesn't%20seem%20to%20work%20no%20mater%20what%20options%20I%20try.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-104700%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-104700%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Cian%20and%20thanks%20for%20responding.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tried%20this%20originally%20but%20it%20wouldn't%20work%20for%20me.%20I%20will%20play%20around%20with%20it%20a%20little%20more%20to%20see%20if%20I%20can%20get%20it%20to%20work%20for%20me.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-104680%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-104680%22%20slang%3D%22en-US%22%3E%3CP%3EI%20enabled%20this%20on%20my%20test%20tenant%20to%20see%20if%20I%20could%20help.%26nbsp%3B%20You%20should%20be%20able%20to%20add%20an%20exception%20to%20permit%20these%20specific%26nbsp%3Baddresses%20to%20receive%20auto%20forwarded%20emails.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20you%20got%20as%20far%20as%20going%20into%20the%20Exchange%20Admin%20Center%20and%20in%20Mail%20Flow%2C%20listed%20in%20rules%20there%20would%20be%20an%20entry%20like%20'Client%20Rules%20To%20External%20Block%20-%20Secure%20Score%209%2F8%2F2017'.%20Editing%20this%2C%20there%20is%20an%20Except%20if..%20add%20exception%20button.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EClick%20this%20and%20add%20the%20required%20exceptions%2C%20for%20example%20using%20%22The%20recipient...%22%20'is%20this%20person%26nbsp%3Boption'.%26nbsp%3B%20I%20think%20that%20should%20work%20anyway%20but%20you%20might%20need%20to%20play%20around%20with%20the%20options.%26nbsp%3B%20Good%20luck.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20781px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F19845iEAA9335306CA2737%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Rule.gif%22%20title%3D%22Rule.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-104655%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-104655%22%20slang%3D%22en-US%22%3E%3CP%3EI%20think%20this%20is%20a%20great%20rule...%20However%2C%20I%20am%20trying%20to%20setup%20an%20exception%20but%20cannot%20seem%20to%20get%20it%20to%20work.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20provide%20instructions%20on%20how%20best%20to%20do%20this%3F%20See%20below...%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20need%20to%20setup%20a%20rule%20that%20will%20redirect%20a%20message%20to%20four%20external%20email%20addresses.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-971434%22%20slang%3D%22en-US%22%3ERe%3A%20Secure%20Score%20-%20New%20Client%20External%20Rules%20Forwarding%20Block%20control%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-971434%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F2395%22%20target%3D%22_blank%22%3E%40Cian%20Allner%3C%2FA%3EJust%20looking%20into%20using%20Secure%20Score%20for%20appling%20this%20transport%20rule%2C%20I%20can%20see%20this%20thread%20is%20a%20couple%20of%20years%20old.%26nbsp%3B%20There%20portal%20looks%20different%20from%20your%20screenshot%20and%20no%20option%20I%20can%20find%20to%20%22Apply%22%20this%20rule%3F%26nbsp%3B%20Has%20this%20function%20gone%20now%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Cian Allner
Trusted Contributor

Secure Score can now help stop data exfiltration with client created rules, that auto-forwards email from users mailboxes to an external email address.  This is apparently an increasingly common data leakage method that is being successfully used by 'bad actors'.

 

Secure Score has a new security control called 'Client Rules Forwarding Blocks' that implements a Transport Rule to help mitigate client created rules that Auto-Forward to external addresses.  

 

Secure Score Client Rules Forwarding Block.png

 

If enabled, this will apply the following logic via a transport rule:

 

IF The Sender is located ‘Inside the organization’ 
AND IF The Recipient is located ‘Outside the organization’
AND IF The message type is ‘Auto-Forward’
THEN Reject the message with the explanation ‘External Email Forwarding via Client Rules is not permitted’.

This feature is now live within Secure Score.  See the announcement here for further details - Mitigating Client External Forwarding Rules with Secure Score.  

 

Perhaps these sorts of announcements could be posted to this community blog in the future like there have been for previous Secure Score new features? 

7 Replies

I think this is a great rule... However, I am trying to setup an exception but cannot seem to get it to work. 

 

Can someone provide instructions on how best to do this? See below... 

 

I am need to setup a rule that will redirect a message to four external email addresses.

Solution

I enabled this on my test tenant to see if I could help.  You should be able to add an exception to permit these specific addresses to receive auto forwarded emails.

 

Have you got as far as going into the Exchange Admin Center and in Mail Flow, listed in rules there would be an entry like 'Client Rules To External Block - Secure Score 9/8/2017'. Editing this, there is an Except if.. add exception button. 

 

Click this and add the required exceptions, for example using "The recipient..." 'is this person option'.  I think that should work anyway but you might need to play around with the options.  Good luck.

 

Rule.gif

 

Hey Cian and thanks for responding. 

 

I tried this originally but it wouldn't work for me. I will play around with it a little more to see if I can get it to work for me. 

 

Thank you! 

Hi. Any updates on this? 

I'm not able to add an exception either. It doesn't seem to work no mater what options I try.

 

Thanks

Any luck getting this to work?

Does this apply to Microsoft Flows that auto-forward email?  @Cian Allner 

@Cian AllnerJust looking into using Secure Score for appling this transport rule, I can see this thread is a couple of years old.  There portal looks different from your screenshot and no option I can find to "Apply" this rule?  Has this function gone now?

 

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies