M365DEF-003: Threat intelligence configuration
- Platform
- Entra ID / M365
- Category
- Defender for Office 365
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Threat intelligence capabilities in Microsoft Defender for Office 365 provide visibility into the threat landscape targeting your organization, including campaign views, threat analytics, and threat tracker insights. Without utilizing threat intelligence features, security teams lack the context needed to understand whether their organization is being targeted by specific threat actors or attack campaigns. Proper threat intelligence configuration enables proactive defense and informed security decision-making.
Recommended value
Threat Explorer and real-time detections actively monitored; threat trackers configured for priority threats; automated investigation and response enabled
Remediation
Ensure that security analysts have access to Threat Explorer or real-time detections views and are trained to use them for investigating email-based threats and campaigns. Configure threat trackers to monitor for specific threat categories relevant to your industry and organization profile. Enable automated investigation and response (AIR) capabilities to automatically investigate and remediate detected threats, reducing the time between detection and response for common threat patterns.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Framework mappings
- NIST SP 800-53
- SI-5