M365DEF-001: Preset security policy audit

Platform
Entra ID / M365
Category
Defender for Office 365
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Preset security policies in Microsoft Defender for Office 365 provide Microsoft-recommended configurations for anti-spam, anti-phishing, anti-malware, Safe Attachments, and Safe Links as a unified policy bundle. Organizations that do not leverage preset policies or equivalent custom configurations may have inconsistent protection levels across different threat protection features. Verifying that the Standard or Strict preset policy is applied ensures a comprehensive and consistently maintained baseline.

Recommended value

Standard Protection preset policy applied to all users at minimum; Strict Protection applied to priority accounts and executives

Remediation

Enable the Standard Protection preset security policy and assign it to all users to establish a Microsoft-recommended security baseline for email threat protection. Apply the Strict Protection preset policy to priority accounts, executives, and high-value targets who are most likely to be targeted by sophisticated attacks. If custom policies are preferred over presets, verify that each custom policy meets or exceeds the settings defined in the Standard or Strict preset configuration.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365DEF-001
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.DEFENDER.1.1v1, MS.DEFENDER.1.2v1, MS.DEFENDER.1.3v1
NIST SP 800-53
SI-3, SI-8
CIS M365 Benchmark
2.1.8