Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Mailbox forwarding during offboarding: are your controls catching it?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: A departing finance manager created a first-ever inbox forwarding rule to a personal Gmail and the case was flagged before offboarding disabled the account, even though login, device, and phishing-resistant MFA all looked clean, according to Artemis Security. The finding shows that strong authentication can coexist with mailbox-state abuse that survives account disablement.

NHIMG editorial — based on content published by Artemis Security: the offboarding forwarding-rule detection case

By the numbers:

  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes , and as quickly as 9 minutes in some cases.

Questions worth separating out

Q: How should security teams handle mailbox forwarding during offboarding?

A: Security teams should treat mailbox forwarding as part of identity lifecycle control, not as an email-only issue.

Q: Why do strong MFA and managed devices not stop internal email exfiltration?

A: Because they prove who authenticated, not what the user did after login.

Q: What breaks when offboarding only disables the primary account?

A: The lifecycle control remains incomplete.

Practitioner guidance

  • Join mailbox-rule monitoring to leaver workflows Alert when a user creates or edits an external forwarding rule within the offboarding window, especially after a termination date appears in the identity profile.
  • Enumerate mailbox state during every offboarding Check inbox rules, mailbox forwarding attributes, and delegate grants before account disablement so message routing cannot outlive the identity.
  • Rank first-ever forwarding rules as high-risk Score a new rule against the mailbox’s full history, not a fixed lookback window, because novelty is the key signal in this pattern.

What's in the full article

Artemis Security's full breach analysis covers the operational detail this post intentionally leaves for the source:

  • The exact detection logic used to correlate first-ever rule creation with leaver status and personal destination matching.
  • The raw event sequence from identity profile change to mailbox rule creation to offboarding disablement.
  • The triage workflow for confirming mailbox state, session legitimacy, and message exposure before account closure.
  • The practical hunting pattern for rule novelty across Exchange and similar mailbox platforms.

👉 Read Artemis Security's analysis of the offboarding forwarding-rule detection case →

Mailbox forwarding during offboarding: are your controls catching it?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Mailbox forwarding during offboarding is a governance failure, not an authentication failure. The article shows a clean login path that still produced a risky mailbox change because the control problem sat above the session layer. Lifecycle state, mailbox history, and destination risk mattered more than MFA strength. That means offboarding governance must treat mailbox state as part of identity, not as a separate email-admin concern.

A few things that frame the scale:

  • 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared with nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.

A question worth separating out:

Q: Who is accountable when a departing employee leaves a forwarding rule in place?

A: Accountability usually spans IAM, email administration, and HR lifecycle owners because the risk sits at the boundary between identity status and mailbox configuration. If the programme treats offboarding as only credential revocation, no one owns the message-routing layer that keeps the risk alive.

👉 Read our full editorial: Mailbox forwarding rules expose offboarding blind spots in IAM



   
ReplyQuote
Share: