# Settings
$UserPrincipalName = "admin@constructtechservices.com"
$EnableExternalTagging = $true
$ExternalTaggingAllowedDomains = @{Add="emberkom.com", "ef-capital.com", "elysionconstruction.com", "elysioncreations.com", "tesseractrentals.com", "arcadiapropertyservices.com"}
$BypassSenderDomains = @(
"emberkom.com",
"notify.emberkom.com",
"ef-capital.com",
"elysionconstruction.com",
"elysioncreations.com",
#"constructtechservices.com",
"tesseractrentals.com",
"arcadiapropertyservices.com"
)
$SetImpersonationRule = $true
$SetSuspiciousEmailRule = $true
$SetGeneralExternalEmailRule = $true
# Connect to EOL
Connect-ExchangeOnline -UserPrincipalName $UserPrincipalName
# Enable/disable external tagging for Outlook clients
If ( (Get-ExternalInOutlook).Enabled -ne $EnableExternalTagging ) {
If ( $EnableExternalTagging ) {
Write-Output "Enabling external email tagging"
} Else {
Write-Output "Disabling external email tagging"
}
If ( $EnableExternalTagging -and $ExternalTaggingAllowedDomains ) {
Set-ExternalInOutlook -Enabled $EnableExternalTagging -AllowList $ExternalTaggingAllowedDomains
} Else {
Set-ExternalInOutlook -Enabled $EnableExternalTagging
}
}
# Impersonation Rule
If ( $SetImpersonationRule ) {
$ImpersonationEmailDisclaimerTitle = "Warning:"
$ImpersonationEmailDisclaimerText = "This appears to be a fradulent email attempting to impersonate someone inside your organization. Do not click on links or open attachments unless you are certain this email is safe."
$ImpersonationRuleName = "Impersonation Warning"
$ImpersonationDisclaimer = '
|
' + $ImpersonationEmailDisclaimerTitle + ' ' + $ImpersonationEmailDisclaimerText + '
|
'
# Set the transport rule for user impersonation
$DisplayNames = (Get-EXOMailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox).DisplayName
$ImpersonationTransportRule = Get-TransportRule | Where-Object { $_.Name -eq $ImpersonationRuleName }
If ( $ImpersonationTransportRule ) {
Write-Output "Updating transport rule: ${ImpersonationRuleName}"
Set-TransportRule -Identity $ImpersonationRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-HeaderMatchesMessageHeader From `
-HeaderMatchesPatterns $DisplayNames `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule updated"
} Else {
Write-Output "Creating transport rule: ${ImpersonationRuleName}"
New-TransportRule -Name $ImpersonationRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-HeaderMatchesMessageHeader From `
-HeaderMatchesPatterns $DisplayNames `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule created"
}
}
# Suspicious Email Rule
If ( $SetSuspiciousEmailRule ) {
$SuspiciousEmailDisclaimerTitle = "Caution:"
$SuspiciousEmailDisclaimerText = "This is a suspicious email from outside your organization. Please be cautious when clicking links or opening attachments."
$SuspiciousEmailRuleName = "Suspicious Email Warning"
$SuspiciousEmailDisclaimer = '
|
' + $SuspiciousEmailDisclaimerTitle + ' ' + $SuspiciousEmailDisclaimerText + '
|
'
# This list is copied from: https://github.com/SwiftOnSecurity/PhishingRegex/blob/master/PhishingRegex.txt
$SuspiciousEmailPatterns = @(
'blocked\ your?\ online',
'suspicious\ activit',
'updated?\ your\ account\ record',
'Securely\ \S{3,4}\ one(\ )?drive',
'Securely\ \S{3,4}\ drop(\ )?box',
'Securely\ \S{3,4}\ Google\ Drive',
'sign\ in\S{0,7}(with\ )?\ your\ email\ address',
'Verify\ your\ ID\s',
'dear\ \w{3,8}(\ banking)?\ user',
'chase\S{0,10}\.html"',
'\b(?<=https?://)(www\.)?icloud(?!\.com)',
'(?
|
' + $GeneralExternalEmailDisclaimerTitle + ' ' + $GeneralExternalEmailDisclaimerText + '
|
'
# Set the transport rule for all external emails
$GeneralExternalEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $GeneralExternalEmailRuleName }
If ( $GeneralExternalEmailRule ) {
Write-Output "Updating transport rule: ${GeneralExternalEmailRuleName}"
Set-TransportRule -Identity $GeneralExternalEmailRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule updated"
} Else {
Write-Output "Creating transport rule: ${GeneralExternalEmailRuleName}"
New-TransportRule -Name $GeneralExternalEmailRuleName `
-FromScope NotInOrganization `
-SentToScope InOrganization `
-ExceptIfSenderDomainIs $BypassSenderDomains `
-ApplyHtmlDisclaimerLocation Prepend `
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
-ApplyHtmlDisclaimerFallbackAction Wrap
Write-Output "Transport rule created"
}
}
# Close connection to EOL
Disconnect-ExchangeOnline -Confirm:$false | Out-Null