M365EXO-030: Malware emails quarantined or dropped (MS.EXO.10.2)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.10.2 requires that emails identified as containing malware be quarantined or dropped. Detection alone is insufficient if the malicious message is still delivered. The anti-malware policy must take a removal action so users cannot interact with messages found to contain malware.

Recommended value

Anti-malware policy action quarantines or drops messages identified as malware (no deliver-with-warning action)

Remediation

Configure the anti-malware policy so messages identified as containing malware are quarantined or dropped rather than delivered. Verify no policy is set to deliver malware-positive messages with only a warning. Confirm administrator notifications are enabled so the security team is alerted on detections.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-030
ScenarioExpected verdict
cleanPASS
emptyFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-3
MITRE ATT&CK
T1566.001