Because they prove who authenticated, not what the user did after login. A trusted session can still create forwarding rules, redirect mail, or alter mailbox behaviour. The control gap appears when identity teams assume authentication quality is the same as action legitimacy, especially during leaver processing.
Why This Matters for Security Teams
Strong MFA and managed devices are valuable because they reduce account takeover risk, but they do not verify whether a legitimate session is being used for legitimate action. Internal email exfiltration often happens after authentication, when an active mailbox session is already trusted and the attacker only needs the ability to change forwarding, create transport rules, or export messages. That is why identity assurance and action assurance are different problems.
NHIMG’s research on the Microsoft Midnight Blizzard breach and the Top 10 NHI Issues both reinforce the same operational lesson: trusted credentials can still be used for harmful post-authentication actions when monitoring stops at login. The NIST Cybersecurity Framework 2.0 is useful here because it pushes teams to look beyond access provisioning and into continuous detection, response, and governance.
In practice, many security teams encounter mailbox exfiltration only after forwarding rules have already been planted and evidence has already been removed, rather than through intentional detection of the action itself.
How It Works in Practice
The core failure is assuming that authenticated equals authorized. MFA proves the session was started by the right person or device, but email platforms often allow high-risk actions inside that session unless additional controls are applied. A managed endpoint may reduce malware and theft, yet it does not stop a valid user session from creating persistence in the mailbox or redirecting content out of the environment.
Current best practice is to separate login assurance from action control. That means combining mailbox activity monitoring, conditional access, anomaly detection, and explicit approval for sensitive changes. For identity and access teams, the useful question is not only “who signed in?” but “what is this session trying to do right now?” The difference matters most for leaver workflows, support accounts, and highly connected executives where mailbox trust is broad.
- Restrict forwarding and inbox rule creation to approved administrative workflows.
- Monitor for bulk export, unusual mailbox delegation, and new external recipients.
- Apply tighter controls to privileged mailboxes and accounts with sensitive business access.
- Use conditional access signals, but do not treat them as proof that every post-login action is safe.
NHIMG’s NHI Lifecycle Management Guide and Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs are relevant because they frame identity controls as lifecycle problems, not single-event authentication problems. These controls tend to break down in environments with permissive mailbox delegation, heavy executive assistant workflows, or legacy email systems that cannot inspect or constrain post-login actions well.
Common Variations and Edge Cases
Tighter email controls often increase help desk friction and operational overhead, requiring organisations to balance exfiltration prevention against business speed. That tradeoff is real, especially where executives, finance, legal, or mergers and acquisitions teams rely on frequent mailbox delegation and external sharing.
There is no universal standard for this yet, but current guidance suggests that strong MFA should be treated as a baseline, not a control that closes the email exfiltration problem. In some environments, the real issue is not compromise but misuse of a valid session by a malicious insider or departing employee. In others, compromise happens first and the attacker immediately uses native mail features to hide activity.
Two common edge cases deserve attention. First, leaver processing often fails because access revocation happens after the mailbox has already been used to seed forwarding rules or send sensitive mail. Second, mobile and cloud-native email access can create gaps where device trust is assumed even though the action originated from a legitimate token on a trusted endpoint. For practitioners, the practical answer is to combine identity checks with action-level controls, as reflected in NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives and the external control emphasis in the NIST Cybersecurity Framework 2.0.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Mailbox abuse needs continuous monitoring after authentication. |
| OWASP Non-Human Identity Top 10 | NHI-05 | Long-lived session or token misuse can enable email exfiltration. |
| OWASP Agentic AI Top 10 | A-04 | Trusted identities can still perform harmful actions after login. |
| NIST AI RMF | Action legitimacy in trusted sessions is a governance issue. |
Track post-login email actions continuously and alert on forwarding, delegation, and bulk export.
Related resources from NHI Mgmt Group
- Why do MFA and strong login controls still leave healthcare identity risk?
- Should organisations prioritise external exposure or internal credential governance first?
- How should organisations stop auto-sync from turning desktops into repositories of credentials?
- Why does email exfiltration remain difficult to stop in Microsoft 365?