M365EXO-012: Remote domains auto-forward setting
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Remote domain settings in Exchange Online control message formatting and out-of-office delivery to external domains, including whether auto-forwarding is permitted per domain. The default remote domain (*) may be configured to allow auto-forwarding, which overrides the outbound spam policy and enables data exfiltration through mailbox forwarding rules. This setting must be audited independently from the outbound spam filter to ensure consistent external forwarding controls.
Recommended value
Auto-forwarding disabled on the default remote domain (*) and all custom remote domains unless explicitly required
Remediation
Review the default remote domain (*) configuration and set AutoForwardEnabled to False to prevent automatic forwarding to all external domains. Audit any custom remote domain entries and disable auto-forwarding unless there is a documented business requirement for a specific partner domain. Verify that the remote domain settings align with the outbound spam policy auto-forwarding configuration to ensure consistent enforcement across both control layers.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.EXO.1.1v2
- NIST SP 800-53
- AC-4
- MITRE ATT&CK
- T1114.003