M365EXO-001: Anti-spam policy audit

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Anti-spam policies in Exchange Online Protection filter inbound and outbound email to block unsolicited messages and spam-based phishing campaigns. Misconfigured or default anti-spam settings may not provide adequate protection, allowing malicious emails to reach user inboxes. Customized spam filter policies with appropriate thresholds and actions are essential for reducing the volume of threats delivered to end users.

Recommended value

Custom anti-spam policy with high confidence spam quarantined; bulk email threshold set to 6 or lower; outbound spam alerts enabled

Remediation

Review all anti-spam policies in Exchange Online and ensure that high confidence spam and high confidence phishing are set to quarantine rather than deliver to junk folder. Configure the bulk email threshold to 6 or lower to catch aggressive bulk senders and enable notifications for outbound spam detection. Apply the custom policy to all recipient domains and verify that no user-level overrides are weakening the organizational policy.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-001
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-8
CIS M365 Benchmark
2.1.1