M365EXO-032: Impersonation protection checks enabled (MS.EXO.11.1)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.11.1 recommends that impersonation protection checks be used. Impersonation protection compares sender addresses against known users and domains to flag look-alike addresses (for example, exmple.com versus example.com). Without it, users must manually distinguish near-identical sender addresses, which is unreliable and increases phishing success.

Recommended value

Anti-phish policy with user and/or domain impersonation protection enabled and applied to high-value targets

Remediation

Enable user and domain impersonation protection in an anti-phish policy and apply it to high-value targets such as executives, finance, and IT, plus organizational and key partner domains. Set the action for impersonated messages to quarantine. Note that impersonation protection requires a Defender for Office 365 plan; if unavailable, evaluate a comparable third-party capability.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-032
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-8
MITRE ATT&CK
T1656, T1566