M365EXO-021: Contact folder sharing not open to all domains (MS.EXO.6.1)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Data (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.6.1 requires that contact folders not be shared with all domains. Exchange Online sharing policies can relax the default restriction on outbound contact sharing. A policy that shares contacts with all domains (a '*' domain entry) exposes directory and contact data broadly, creating a data exfiltration avenue and aiding reconnaissance for social engineering.

Recommended value

No sharing policy rule grants contact sharing to the wildcard domain (*); sharing limited to specific approved domains only

Remediation

Review every Exchange Online sharing policy and remove any rule that shares contact folders with the wildcard domain (*). Where external contact sharing is genuinely required, scope it to specific named partner domains rather than all domains. Validate that the default sharing policy does not silently re-enable all-domain contact sharing.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-021
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.EXO.6.1v1
NIST SP 800-53
AC-4, AC-21
MITRE ATT&CK
T1087