How to govern Exchange
A step-by-step guide to governing Exchange with Rencore: detect with 31 policies, review with 14 reports, and remediate with 15 automations.
Governing Exchange means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Exchange with 31 pre-built policies, 14 reports, and 15 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.
Steps
-
Inventory Exchange
Connect Exchange and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Exchange to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Exchange reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Recommended Exchange policies
Grounded in the Rencore catalog. See the full Exchange catalog on the Exchange connector page.
-
Mailboxes near storage quota
Shows mailboxes that have used more than 80% of their prohibit-send quota.
Severity: High -
Inactive mailboxes (90+ days)
Shows mailboxes that have not had any send/receive/read activity for more than 90 days.
Severity: Medium -
Large mailboxes without archive
Shows mailboxes larger than 50 GB that do not have an online archive enabled.
Severity: Medium -
Mailboxes with excessive redirect rules
Shows mailboxes with more than 10 redirect rules; a known attacker-persistence pattern.
Severity: Medium -
Mailboxes auto-replying to all external senders
Shows mailboxes whose auto-reply is enabled and configured to reply to all external senders.
Severity: Medium -
Calendars shared with external users
Shows calendar permissions granted to users outside of the organization.
Severity: Medium -
Tenant allows external auto-forwarding
Detects when the outbound spam policy 'AutoForwardingMode' is not set to 'Off', allowing users to auto-forward mail externally.
Severity: High -
Remote domain permits auto-forward
Detects remote domains where automatic forwarding is allowed.
Severity: High -
Admin audit log disabled
Detects when the Exchange admin audit log is disabled, preventing forensic reconstruction of admin actions.
Severity: High -
Journal rule sends to external recipient
Detects Exchange journal rules whose journal mailbox is in an external domain.
Severity: High -
Transport rule modified
Detects audit events where an Exchange transport rule was created, modified, or removed.
Severity: High -
Mailbox permission granted
Detects audit events where mailbox or recipient permissions were added or removed.
Severity: Medium