M365EXO-022: Calendar detail sharing not open to all domains (MS.EXO.6.2)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Data (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.6.2 requires that calendar details not be shared with all domains. Sharing policies can permit external calendar detail sharing; a rule covering the wildcard domain (*) exposes meeting subjects, locations, and attendee information to any external party. This leaks organizational activity that supports targeted phishing and physical reconnaissance.

Recommended value

No sharing policy rule grants calendar detail sharing (CalendarSharing*) to the wildcard domain (*); sharing limited to specific approved domains, ideally free/busy only

Remediation

Review every Exchange Online sharing policy and remove any rule that shares calendar details with the wildcard domain (*). If external calendar sharing is required, restrict it to specific named domains and prefer free/busy-only levels over full detail. Confirm the default sharing policy does not expose calendar details to all domains.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-022
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.EXO.6.2v1
NIST SP 800-53
AC-4, AC-21
MITRE ATT&CK
T1087