M365EXO-008: Transport rules inventory and analysis
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Exchange Online transport rules (mail flow rules) process email messages in transit and can modify headers, redirect messages, add disclaimers, or bypass security controls. Malicious or misconfigured transport rules can silently redirect email, strip security headers, or bypass spam filtering for specific senders. A comprehensive audit of all transport rules is necessary to identify rules that may weaken security or facilitate data exfiltration.
Recommended value
All transport rules documented with business justification; no rules bypassing spam filtering or security controls without explicit approval
Remediation
Export and review all Exchange Online transport rules, paying particular attention to rules that bypass spam filtering, redirect email to external addresses, or modify message headers. Remove or disable any rules that lack a documented business justification or that were created by accounts that have since been compromised or deprovisioned. Implement a change management process for transport rule creation and modification, and set up audit log alerts for transport rule changes.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-4