Skip to main content
Service

Exchange Online, configured properly and watched

Mail flow, authentication, retention and shared mailboxes managed as a system — including alerting on the inbox rules that signal a compromised account.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Day-to-day management of Exchange Online — mail flow, authentication, retention, shared mailboxes and detection of the signals that indicate a compromised mailbox.

Email is where the business runs

Exchange Online is usually the most business-critical service in a Microsoft 365 tenant and the one that receives the least ongoing attention. It gets configured during migration and then left, while the environment around it changes — new senders, new devices, new staff, new marketing platforms — until something breaks or someone gets compromised.

Managing it means keeping four things current.

Mail flow, documented

Every path mail takes into and out of your tenant: connectors, relays, and every device or application sending on your behalf. The multifunction scanner, the accounting package sending remittances, the booking system, the CRM.

This is almost never written down, which is why the failure is always the same: a device configured three years ago by someone who has left stops sending after a change, and nobody knows how it was set up or which account it used. Inventorying it once turns that from an afternoon into five minutes.

Authentication that stays correct

SPF, DKIM and DMARC are not set-and-forget. Every time the business adds a platform that sends mail as your domain — a new marketing tool, a survey platform, an e-signature service — the SPF record needs to know about it, or that mail starts failing authentication.

The common outcome is that someone adds the new sender by loosening the record rather than extending it correctly, which quietly removes the protection. Keeping it right is ongoing work. See email security for what these records do.

The compromise signal worth watching

If you monitor one thing in Exchange Online, monitor inbox rule creation.

The attack sequence for business email compromise is consistent: obtain credentials, sign in, create a rule that moves or deletes incoming mail so the owner does not see replies, then watch genuine invoice conversations and intervene at the right moment with changed bank details.

That rule creation is a discrete event that can be alerted on. It is cheap to configure and it is how these get caught early rather than after the money has moved.

Leavers

A defined offboarding sequence, applied consistently: sign-in access revoked immediately, mailbox converted to a shared mailbox so the manager retains access without a licence, forwarding configured if the role requires continuity, licence released, and a retention period after which the mailbox is removed.

The alternative — a licensed, active, unmonitored account belonging to someone who left eight months ago — is both a recurring cost and one of the more attractive targets in your tenant.

What you get with JTIT

Concrete deliverables, not vague promises.

Mail flow that is documented

Connectors, relays, and every device or application sending through your tenant, inventoried — so a scanner that stops emailing is a five-minute fix.

Authentication maintained

SPF, DKIM and DMARC kept correct as senders change, rather than configured once and quietly broken by a new marketing platform.

Retention set deliberately

How long mail is kept, and what happens to leavers' mailboxes, decided against your obligations instead of left at defaults.

Compromise signals watched

Alerting on suspicious inbox rule creation and unusual forwarding, which is how mailbox compromise is caught in hours rather than after a payment goes astray.

Shared mailboxes done properly

Shared mailboxes and delegate access configured as intended, and unlicensed where they should be, which is also cheaper.

Leavers handled cleanly

A defined offboarding process — access revoked, mailbox converted or retained, forwarding set where needed, licence released.

How it works

A predictable, no-surprises process.

  1. 01

    Document the current state

    Mail flow, connectors, relays, shared mailboxes, distribution lists, delegates, rules and retention. This is rarely written down anywhere.

  2. 02

    Fix authentication and flow

    SPF, DKIM and DMARC brought correct, unnecessary connectors removed, and any open relay closed.

  3. 03

    Set policy

    Retention, litigation hold where required, external sender warnings, and an offboarding standard for leavers.

  4. 04

    Monitor

    Alerting on inbox rules, forwarding changes and unusual sign-in patterns, reviewed by our engineers rather than emailed to you.

Frequently asked questions

Why does alerting on inbox rules matter so much?

Because it is the single most reliable early signal of a compromised mailbox. Once an attacker has access, the first thing they do is create a rule that forwards or deletes incoming mail, so the real owner does not see replies to the messages being sent in their name. That rule creation is a discrete, detectable event. Alerting on it is how a compromise gets caught within hours instead of three weeks later when a customer asks why the bank details changed.

Do we still need an on-premises Exchange server?

Almost certainly not, and if you have one running solely to manage attributes in a hybrid setup, that is worth reviewing — Microsoft's tooling has moved on and the security exposure of an internet-facing Exchange server is significant. Unpatched on-premises Exchange has been one of the more heavily exploited targets in recent years. If yours exists only for management, decommissioning it is usually the right call.

How should we handle mailboxes when someone leaves?

There is a standard sequence: revoke sign-in access immediately, convert the mailbox to a shared mailbox so it can be accessed by their manager without a licence, set forwarding if appropriate, and decide a retention period after which it is removed. What you should not do is leave a licensed, active account sitting there indefinitely, which is both a cost and a security exposure — a dormant account with a valid password is an attractive target precisely because nobody is watching it.

Our scanner or line-of-business app sends email. How is that handled?

Through an authenticated connector or an SMTP relay, configured deliberately and documented. This is one of the more common causes of mysterious mail failures — a device configured years ago with credentials nobody recorded stops working after an authentication change and nobody knows how it was set up. Inventorying every sender is part of onboarding.

What retention should we set?

It depends on your industry and any regulatory or contractual obligation, so we set it per client rather than applying a default. The general principle is that keeping everything forever is not automatically safer — it increases what is exposed in a breach and what is discoverable in litigation. Deciding deliberately is the point, and doing nothing is a decision by default.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote