By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published January 9, 2026

TL;DR: Intentional data exfiltration over email remains difficult to detect, with KnowBe4 reporting that 94% of organisations have seen data loss and exfiltration in Microsoft 365 and 91% suffered significant fallout. Static DLP and audit-log review alone are not enough when users deliberately bypass safeguards, making behaviour-aware monitoring the practical control gap.


At a glance

What this is: This is an analysis guide on intentional data exfiltration over email and the finding that static DLP rules and audit-log review are leaving major detection gaps.

Why it matters: It matters because email remains a common exfiltration path in Microsoft 365, and IAM, PAM, and SOC teams need controls that detect misuse as behaviour, not just policy violations.

By the numbers:

👉 Read KnowBe4's guide on detecting data exfiltration over email in Microsoft 365


Context

Data exfiltration over email is a governance problem as much as a security one. When users intentionally route sensitive information to personal accounts, traditional policy checks can miss the intent behind the action, especially in Microsoft 365 environments where the legitimate email channel is already trusted.

For identity and access teams, the issue sits at the boundary of user behaviour, data controls, and administrative oversight. The article frames a familiar operational gap: organisations can define email policy, but still fail to detect deliberate rule-breaking when monitoring depends on static DLP and retrospective log review.


Key questions

Q: What breaks when organisations rely on static DLP for email exfiltration detection?

A: Static DLP breaks when users intentionally adapt their behaviour to avoid fixed rules. It can miss personal-email forwarding, disguised attachments, and policy-bypassing workflows that still move sensitive information. Organisations need behavioural detection, not only content matching, because the attacker or insider can change the method faster than rule sets are updated.

Q: Why does email exfiltration remain difficult to stop in Microsoft 365?

A: Microsoft 365 email is a trusted business channel, so malicious or policy-breaking activity can look normal. If teams only monitor content labels or keywords, they miss the user behaviour that reveals intent. The problem is compounded when access governance, mail controls, and SOC monitoring operate separately.

Q: How should security teams measure whether DLP monitoring is actually working?

A: Measure DLP by outcomes, not alert volume. Track mean time to detect, false positive rate, coverage of sensitive data, and the number of prevented exfiltration attempts. If the team cannot show faster detection, fewer false alarms, and broader coverage over time, the control exists on paper but is not delivering reliable protection.

Q: Who is accountable when a misdirected email exposes sensitive data?

A: Accountability usually spans the business owner, the data security team, and the control owner for email governance. Regulators and auditors will care less about intent than about whether the organisation had preventive controls, training, and monitoring appropriate to the sensitivity of the data. The key question is whether the control design was proportionate to the risk.


Technical breakdown

Why static email DLP misses intentional exfiltration

Static DLP works by matching content against fixed rules, such as keywords, file types, labels, or destination addresses. That model is effective for predictable misuse, but it breaks down when a user changes behaviour to avoid the rule set, for example by renaming files, fragmenting content, or sending from approved workflows that still carry sensitive data. In Microsoft 365, the trusted nature of email also makes exfiltration look normal unless the system models context, user intent, and abnormal sending patterns. Practical implication: organisations need detection that evaluates behaviour, not only content matches.

Practical implication: supplement static DLP with behavioural analytics and policy-aware monitoring of email flow patterns.

How audit logs fit into exfiltration detection

Audit logs record what happened after the fact, but they are not a detection strategy on their own. They can show message sent events, mailbox rule changes, forwarding configuration, and access activity, yet they usually require active review, correlation, and investigation before they become actionable. In exfiltration cases, that means the signal often arrives too late to prevent the send or the forward. The control gap is not logging itself, but dependence on retrospective review as the primary means of finding abuse. Practical implication: use audit data to confirm and scope incidents, not as the only line of defence.

Practical implication: treat audit logs as investigative evidence and pair them with real-time alerting and response workflows.

Behaviour-based controls for Microsoft 365 email risk

Behaviour-based controls look for deviations from normal sending, forwarding, attachment, and recipient patterns. They are better suited to intentional exfiltration because they can flag suspicious use even when the content is not obviously sensitive or the user stays within permitted channels. This is especially relevant in Microsoft 365, where user-level trust, mailbox rules, and collaboration workflows can obscure malicious or policy-breaking intent. For identity-led programmes, this is a human identity and access governance issue: legitimate accounts can still be used for harmful data movement. Practical implication: baseline normal email behaviour and alert on deviations that indicate abuse.

Practical implication: establish behavioural baselines for email use and escalate abnormal forwarding or recipient patterns immediately.


Threat narrative

Attacker objective: The objective is to remove sensitive information from Microsoft 365 through a trusted channel without triggering effective prevention or timely detection.

  1. Entry occurs through a legitimate Microsoft 365 user account that already has normal mailbox access and trusted email permissions.
  2. Escalation happens when the user bypasses internal safeguards by using personal email, forwarding rules, or other policy workarounds to move sensitive data out of the environment.
  3. Impact is achieved when sensitive information leaves organisational control and the activity is difficult to distinguish from ordinary email use until after the fact.

NHI Mgmt Group analysis

Static DLP is a control boundary, not a detection model. The article shows why content matching alone cannot keep pace with intentional rule-breaking, especially when users stay inside approved platforms while changing their behaviour. That means the real problem is not the absence of policy, but the gap between policy enforcement and human decision-making. Practitioners should treat static DLP as one layer inside a broader behavioural detection programme.

Behavioural exfiltration risk is a human identity governance problem. When a legitimate account is used to send data to personal email or other out-of-policy destinations, the identity is trusted while the behaviour is not. That creates a boundary failure between IAM, data protection, and SOC monitoring. The named concept here is trusted-channel abuse: misuse of an approved communication path to evade controls. Teams should govern the channel, not just the content.

Audit-log dependence creates detection latency that favours the user, not the defender. Retrospective review can confirm misuse, but it rarely stops the first send or forward. This is why organisations that rely on logs as their main control are effectively accepting delayed discovery. Security programmes need event-driven monitoring, alert triage, and response playbooks that are aligned to email abuse patterns, not just compliance review cycles.

Email exfiltration is a privilege-use issue as much as a data issue. A user who can read, forward, or attach sensitive material can often move it with minimal friction unless access governance and data handling controls are tied together. In practice, this means access reviews, mailbox rule oversight, and DLP tuning must be coordinated. Practitioners should collapse the gap between identity governance and data movement monitoring.

What this signals

Trusted-channel abuse is becoming a useful way to describe a familiar control failure: legitimate channels are used for illegitimate data movement, and static monitoring misses the intent shift. For identity-led programmes, that means access governance and data protection must be coordinated with behavioural telemetry, not managed as separate domains.

When email abuse is detected only after investigation, the programme is already operating with detection latency that favours the insider or compromised account. Teams should expect more pressure to prove that DLP, mailbox controls, and identity monitoring can produce timely, explainable alerts. The right reference points are NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls.

The practical shift is toward measuring whether risky email behaviour is visible within the workflow, not whether logs exist after the fact. That is where exfiltration governance stops being a compliance exercise and becomes an operational control problem.


For practitioners

  • Implement behaviour-based email detection Baseline normal send, forward, attachment, and recipient patterns in Microsoft 365, then alert on deviations that indicate deliberate data movement rather than routine communication.
  • Review mailbox rule and forwarding abuse Monitor for newly created forwarding rules, external redirects, and suspicious inbox automation that can move messages outside organisational visibility before content inspection catches them.
  • Use audit logs for investigation, not primary detection Correlate message events, mailbox changes, and login activity to validate suspected exfiltration, but do not rely on audit-log review as the main control.
  • Align DLP with identity governance Connect DLP exceptions, email permissions, and access review processes so that users with broad communication access are scrutinised for abuse patterns as well as policy violations.

Key takeaways

  • Intentional email exfiltration defeats controls that look only at content and policy labels.
  • Microsoft 365 email abuse is a human identity and governance issue as much as a data security issue.
  • Organisations need behavioural detection, coordinated identity oversight, and audit logs used as evidence rather than the main defence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous monitoring is central to spotting email exfiltration beyond static DLP.
NIST SP 800-53 Rev 5AU-6Audit review supports investigation, but only when correlated and acted on quickly.
MITRE ATT&CKTA0010 , ExfiltrationThe article describes deliberate data movement out of Microsoft 365.

Map email abuse patterns to TA0010 and prioritise alerting on external forwarding and suspicious attachments.


Key terms

  • Email Data Exfiltration: Email data exfiltration is the unauthorized transfer of sensitive information through email, attachments, links, or forwarding rules. It may be accidental or deliberate, but the governance challenge is the same: prove whether the sender, recipient, and content matched policy and access intent.
  • Static Email DLP: A content-based control that flags or blocks messages using fixed rules such as keywords, labels, attachments, or destination addresses. It helps with known policy violations, but it is weak against users who change behaviour, disguise content, or use approved workflows to bypass controls.
  • Behavioral Detection: A monitoring approach that looks for unusual activity rather than relying only on static inventories. For SaaS integrations, it detects drift in token use, data movement, timing, and endpoint behavior so teams can spot compromise, misuse, or automation that no longer matches its expected pattern.

What's in the full article

KnowBe4's full guide covers the operational detail this post intentionally leaves for the source:

  • Tactics employees use to bypass internal safeguards and route sensitive information to personal email accounts
  • Detection and monitoring approaches for Microsoft 365 email exfiltration beyond static DLP rules
  • The operational limitations of audit-log review when investigating intentional data loss
  • Behaviour-based controls practitioners can use to improve alerting and reduce detection latency

👉 KnowBe4's full guide covers employee tactics, DLP limitations, and detection approaches in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners connect identity controls to the broader programme risks they manage.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org