Microsoft 365 Mailbox and Mail Flow Governance: Why Controlling Logins Is Not the Same as Controlling Access
Maintaining a secure Microsoft 365 environment requires a clear distinction between who can log in to a system and what they can actually do once authenticated. While many organisations in South East Queensland have implemented strong identity controls (such as multi-factor authentication (MFA) and conditional access policies), these measures only solve the first half of the security equation. Controlling the login process is not the same as governing the mailbox access and mail-flow rules that operate silently behind the scenes.
Identity governance ensures that only authorised individuals can sign in to their accounts. However, mailbox and mail-flow governance focuses on the internal permissions and routing logic that determine who can read specific emails and where those emails are sent. Without this second layer of governance, a business may inadvertently allow sensitive data to accumulate in accessible pockets or permit hidden rules to exfiltrate information without detection.
The Two Layers of Email Governance
Email security is often viewed as a single discipline, yet it is more accurately managed in two distinct layers. The first is the domain layer, which involves authenticating that mail sent from a domain is legitimate. This is the focus of Email Security Governance, where protocols like SPF, DKIM, and DMARC prevent external impersonation.
The second layer—the mailbox and access layer—is where internal governance takes place. This layer governs the relationship between users and mailboxes, as well as the rules that dictate the movement of mail. Even if the domain layer is perfectly configured, a failure at the mailbox layer can lead to significant data exposure. An organisation might successfully block an external attacker from spoofing its domain, only to have an internal account compromise result in a hidden auto-forwarding rule that copies every invoice to an external address. Effective managed IT services treat these two layers as complementary but separate governance requirements.
Lever 1: The Documented Mailbox Access Register
The primary challenge in mailbox governance is visibility. In a standard Microsoft 365 environment, permissions are often granted organically as needs arise. A staff member might be given “Full Access” to a director’s mailbox to help manage a busy period, or a temporary contractor might be granted “Send As” permissions for a shared accounts mailbox.
Proper governance requires a centralised, documented register of all mailbox permissions. This register should detail:
- Full Access (Read and Manage): Who has the ability to open a mailbox, read all its contents, and manage its folders.
- Send As: Who can send emails that appear to originate directly from another user’s or shared mailbox.
- Send on Behalf: Who can send mail where the recipient sees that the message was sent by one person on behalf of another.
By maintaining a register rather than relying on the active configuration in the Exchange Admin Center alone, a business creates a “source of truth” that can be audited against business requirements. If a name appears in the system permissions but not on the authorised register, it indicates a governance failure that must be remediated.
Lever 2: Periodic Access Review
Permissions in Microsoft 365 are prone to “access creep”—a phenomenon where access is granted for a specific, time-limited task but is never revoked. Over several years, a single user can accumulate permissions to dozens of mailboxes, many of which they no longer require for their current role.
A scheduled governance review ensures that permissions are pruned regularly. This process mirrors the principles of Identity Lifecycle Governance, where access is granted at the start of employment and strictly revoked upon departure. A common failure occurs when a staff member leaves the organisation and their mailbox is delegated to their replacement or a manager. If those permissions are not reviewed six months later, the business ends up with a web of delegated access that no longer serves a functional purpose but increases the security risk.
Lever 3: Auto-forwarding and Inbox-rule Monitoring
Mail-flow governance extends beyond human access to include the automated logic applied to emails. Attackers who successfully compromise a mailbox through techniques like Business Email Compromise (BEC) often avoid changing passwords or taking overt actions. Instead, they create silent inbox rules.
These rules might be configured to:
- Forward all incoming mail containing the word “invoice” or “payment” to an external Gmail address.
- Move all incoming mail from a specific vendor to the “Deleted Items” folder so the legitimate user never sees it.
- Mark all sent items as read and move them to a hidden folder to hide the attacker’s outbound communications.
Governance in this area involves the proactive monitoring of all auto-forwarding and inbox rules. While some forwarding is legitimate (such as a shared mailbox forwarding to a ticketing system), any rule that sends data to an external or personal address should be treated as a potential data-leakage event until verified.
Lever 4: Alerting on New Mail-flow Rules
Monitoring is a reactive governance control, while alerting provides a proactive safeguard. A governed Microsoft 365 environment should be configured to trigger immediate alerts whenever a new mail-flow or transport rule is created.
Transport rules operate at the tenant level and can affect every mailbox in the organisation. If an unauthorised person (or a misinformed administrator) creates a rule to bypass spam filters for a specific domain, the entire business is immediately exposed. Alerting ensures that these changes are caught within minutes rather than months. This is a critical step in moving from a “set and forget” mentality to a state of continuous governance.

Common SMB Pitfalls in Mailbox Governance
Small and medium-sized businesses often struggle with mailbox governance because the technical “defaults” in Microsoft 365 prioritise ease of use over strict control. This often leads to several common pitfalls that increase risk.
One-off Permissions That Become Permanent
Access is frequently granted for a single project or a week of leave coverage. Because there is no governance trigger to remove that access once the project ends, the permission remains. Years later, a user may still have full access to the HR or Finance director’s mailbox without anyone in the business realising it.
The “Leaver Delegation” Trap
When an employee leaves, their manager often requests access to the mailbox to ensure no client queries are missed. While this is operationally sound, it often lacks an expiry date. When that manager eventually moves to a different department or also leaves the company, the original “leaver mailbox” remains delegated to an ever-growing list of people, creating a sprawl of accessible data that is difficult to track.
Unmonitored Shared Mailboxes
Shared mailboxes for generic functions (such as info@, sales@, or accounts@) are frequently the most ungoverned areas of an IT environment. Because they do not have a single “owner” like an individual mailbox, permissions are often granted to entire groups or lists. Over time, the list of people who can read sensitive financial or client data in these mailboxes grows far beyond what is necessary.
Hidden External Forwarding
Without a policy that explicitly blocks or alerts on external auto-forwarding, staff members may set up rules to forward work emails to their personal accounts for convenience. While well-meaning, this moves corporate data into an ungoverned personal environment where the business has no control over security, retention, or recovery. This is also the exact mechanism used by BEC attackers to exfiltrate data silently.

Establishing a Governance Cadence
Controlling who can log in to an email account is a foundational security step, but it is not the finish line. True governance requires a shift in focus toward the permissions and rules that exist inside the tenant. By implementing a documented access register, conducting periodic reviews, and monitoring mail-flow rules, a business can ensure that access is limited to what is truly necessary.
For organisations that handle sensitive client information or financial data, these controls are not optional extras; they are core components of a stable and secure technology environment. If an organisation has not reviewed its mailbox permissions or mail-flow rules in the last six months, it is likely that “access creep” has already occurred.
Organisations looking to review who can access which mailboxes and what rules are moving their mail can speak with Moreton Bay IT to discuss a structured review of mailbox and mail-flow configurations.
