Day-to-day management of Exchange Online — mail flow, authentication, retention, shared mailboxes and detection of the signals that indicate a compromised mailbox.
Email is where the business runs
Exchange Online is usually the most business-critical service in a Microsoft 365 tenant and the one that receives the least ongoing attention. It gets configured during migration and then left, while the environment around it changes — new senders, new devices, new staff, new marketing platforms — until something breaks or someone gets compromised.
Managing it means keeping four things current.
Mail flow, documented
Every path mail takes into and out of your tenant: connectors, relays, and every device or application sending on your behalf. The multifunction scanner, the accounting package sending remittances, the booking system, the CRM.
This is almost never written down, which is why the failure is always the same: a device configured three years ago by someone who has left stops sending after a change, and nobody knows how it was set up or which account it used. Inventorying it once turns that from an afternoon into five minutes.
Authentication that stays correct
SPF, DKIM and DMARC are not set-and-forget. Every time the business adds a platform that sends mail as your domain — a new marketing tool, a survey platform, an e-signature service — the SPF record needs to know about it, or that mail starts failing authentication.
The common outcome is that someone adds the new sender by loosening the record rather than extending it correctly, which quietly removes the protection. Keeping it right is ongoing work. See email security for what these records do.
The compromise signal worth watching
If you monitor one thing in Exchange Online, monitor inbox rule creation.
The attack sequence for business email compromise is consistent: obtain credentials, sign in, create a rule that moves or deletes incoming mail so the owner does not see replies, then watch genuine invoice conversations and intervene at the right moment with changed bank details.
That rule creation is a discrete event that can be alerted on. It is cheap to configure and it is how these get caught early rather than after the money has moved.
Leavers
A defined offboarding sequence, applied consistently: sign-in access revoked immediately, mailbox converted to a shared mailbox so the manager retains access without a licence, forwarding configured if the role requires continuity, licence released, and a retention period after which the mailbox is removed.
The alternative — a licensed, active, unmonitored account belonging to someone who left eight months ago — is both a recurring cost and one of the more attractive targets in your tenant.