M365EXO-024: Data loss prevention solution in use (MS.EXO.8.1)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Data (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.8.1 requires that a DLP solution be used, offering services comparable to the native Microsoft solution. DLP detects sensitive information in Exchange Online mail and prevents unauthorized disclosure. Without DLP, users may inadvertently or maliciously send sensitive data outside the organization with no automated detection or blocking.

Recommended value

At least one active DLP policy scoped to the Exchange Online workload

Remediation

Deploy a DLP solution that covers the Exchange Online mail workload and confirm at least one policy is enabled and applied. If using the native Microsoft DLP capability, create a policy in the compliance portal scoped to Exchange email. Validate that the policy is in enforce mode rather than test-only so disclosures are actually blocked.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-024
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-4, SC-7
MITRE ATT&CK
T1048