Get-InboxRule
SafeInbox rules audit
Get-InboxRule -Mailbox <user>
Lists a mailbox's rules — attackers plant forward-and-hide rules, so this is mandatory in compromise triage.
Examples
Get-InboxRule -Mailbox taro | ? {$_.ForwardTo -or $_.RedirectTo}Just the forwarding rules
Syntax
Get-InboxRule -Mailbox id / Remove-InboxRule -Mailbox id -Identity rule
Before you run it
Reads are safe; confirm before removals.
Related commands
- Get-MgAuditLogSignInSign-in logs
- Revoke-MgUserSignInSessionRevoke sign-ins
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store