M365EXO-024: Data loss prevention solution in use (MS.EXO.8.1)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Data (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.8.1 requires that a DLP solution be used, offering services comparable to the native Microsoft solution. DLP detects sensitive information in Exchange Online mail and prevents unauthorized disclosure. Without DLP, users may inadvertently or maliciously send sensitive data outside the organization with no automated detection or blocking.
Recommended value
At least one active DLP policy scoped to the Exchange Online workload
Remediation
Deploy a DLP solution that covers the Exchange Online mail workload and confirm at least one policy is enabled and applied. If using the native Microsoft DLP capability, create a policy in the compliance portal scoped to Exchange email. Validate that the policy is in enforce mode rather than test-only so disclosures are actually blocked.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- NIST SP 800-53
- SI-4, SC-7
- MITRE ATT&CK
- T1048