M365EXO-031: Post-delivery malware scanning enabled (MS.EXO.10.3)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.10.3 requires that email scanning be capable of reviewing emails after delivery. Malware signatures update continuously, so a message benign at delivery may later be recognized as malicious. Zero-hour auto purge (ZAP) retroactively removes such messages from mailboxes, reducing the window of exposure.

Recommended value

Zero-hour auto purge (ZAP) enabled on all anti-malware policies (ZapEnabled = True)

Remediation

Enable zero-hour auto purge (ZAP) on every anti-malware policy so messages later identified as malware are removed from mailboxes after delivery. Confirm ZAP is enabled across all policies, not just the default. Where a comparable third-party solution is used, verify it provides equivalent post-delivery remediation.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-031
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-3
MITRE ATT&CK
T1566.001