M365EXO-010: External sender warnings

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

External sender identification helps users recognize when an email originates from outside the organization, reducing the effectiveness of impersonation and social engineering attacks. Without visible external sender indicators, users may not distinguish between internal colleagues and external senders spoofing internal display names. Configuring external sender tags or mail tips provides a visual cue that prompts users to exercise additional caution.

Recommended value

External sender tag or mail tip enabled to visually identify emails from external senders

Remediation

Enable the external sender identification feature in the Exchange Online anti-phishing policy to display a visual indicator on emails from external senders. Consider implementing a transport rule that prepends '[External]' to the subject line of inbound emails from outside the organization as an additional visual warning. Communicate the change to end users and provide guidance on how to identify and respond to suspicious external emails.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-010
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.EXO.7.1v1
NIST SP 800-53
SI-8
CIS M365 Benchmark
2.1.7