M365EXO-022: Calendar detail sharing not open to all domains (MS.EXO.6.2)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Data (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.6.2 requires that calendar details not be shared with all domains. Sharing policies can permit external calendar detail sharing; a rule covering the wildcard domain (*) exposes meeting subjects, locations, and attendee information to any external party. This leaks organizational activity that supports targeted phishing and physical reconnaissance.
Recommended value
No sharing policy rule grants calendar detail sharing (CalendarSharing*) to the wildcard domain (*); sharing limited to specific approved domains, ideally free/busy only
Remediation
Review every Exchange Online sharing policy and remove any rule that shares calendar details with the wildcard domain (*). If external calendar sharing is required, restrict it to specific named domains and prefer free/busy-only levels over full detail. Confirm the default sharing policy does not expose calendar details to all domains.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.EXO.6.2v1
- NIST SP 800-53
- AC-4, AC-21
- MITRE ATT&CK
- T1087