A really cool policy in MCAS that enables you to not only monitor and be alerted when someone (e.g. bad actor or malicious employee) decides to forward all their email to an external address -- but also govern and apply a policy that suspends the account, runs a PowerAutomate playbook, or tells AAD that your user account has been compromised!
If you found value in this video please like it and be sure to subscribe so you can be notified when I upload new videos. You can also follow me on Twitter @SosemanMatt.