Reference
Transport Rule
Exchange mail flow / transport rules. Top governance signal for BEC and data exfiltration patterns.
Part of the Exchange inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Weekly | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Apply Rights Protection Template | String | {{TransportRule.ApplyRightsProtectionTemplate}} | |
| Blind Copy To | String[] | Recipients silently BCC'd on the message. | {{TransportRule.BlindCopyTo}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{TransportRule.CreatedTime}} |
| Rule Name | String | {{TransportRule.DisplayName}} | |
| From Scope | String | Allowed values: InOrganization, NotInOrganization. | {{TransportRule.FromScope}} |
| Has Classification | String | {{TransportRule.HasClassification}} | |
| Has External Redirect | Boolean | True when any RedirectMessageTo or BlindCopyTo target is in an external domain. | {{TransportRule.HasExternalRedirect}} |
| Last Modified By | String | {{TransportRule.LastModifiedBy}} | |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{TransportRule.LastModifiedTime}} |
| Mode | String | Rule enforcement mode: Enforce, Audit, or AuditAndNotify. Allowed values: Audit, AuditAndNotify, Enforce. | {{TransportRule.Mode}} |
| Priority | Int32 | Order in which the rule is evaluated (0 = first). | {{TransportRule.Priority}} |
| Redirect Message To | String[] | Recipients the message is silently redirected to. | {{TransportRule.RedirectMessageTo}} |
| Reject Message Reason | String | {{TransportRule.RejectMessageReasonText}} | |
| Risk Score | Int32 | Stores risk score | {{TransportRule.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{TransportRule.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{TransportRule.RiskScoreValue}} |
| Description | String | {{TransportRule.RuleDescription}} | |
| Sent To Scope | String | Allowed values: ExternalNonPartner, ExternalPartner, InOrganization, NotInOrganization. | {{TransportRule.SentToScope}} |
| State | String | Whether the rule is enabled or disabled. Allowed values: Disabled, Enabled. | {{TransportRule.State}} |
| Subject Contains Words | String[] | {{TransportRule.SubjectContainsWords}} | |
| Rule Id | String | {{TransportRule.TransportRuleId}} |
Relations
This object does currently not have any relations.
Segments
| Segment | Description |
|---|---|
| Audit-mode transport rules | Transport rules running in audit or audit-and-notify mode. |
| Enabled transport rules | Transport rules that are currently enabled and enforcing. |
| Rules with external redirect | Transport rules that redirect messages to external recipients. |
Actions
This object does currently not have any actions.
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Transport rule redirecting to external recipients | High | Detects mail flow rules that silently redirect or BCC messages to external domains. |