M365EXO-034: AI-based phishing detection in use (MS.EXO.11.3)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.11.3 recommends an AI-based phishing detection tool comparable to EOP Mailbox Intelligence. Mailbox intelligence builds a model of a user's normal correspondents to detect anomalous senders that rule-based filters miss. Without an AI-based layer, novel or highly targeted phishing is more likely to evade detection.

Recommended value

Anti-phish policy with mailbox intelligence enabled (EnableMailboxIntelligence = True) and protection action configured

Remediation

Enable mailbox intelligence in the anti-phish policy and configure the mailbox intelligence protection action to handle detected impersonations. Apply the policy to all users. Mailbox intelligence requires a Defender for Office 365 plan; where unavailable, evaluate a comparable AI-based third-party phishing detection capability.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-034
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-8
MITRE ATT&CK
T1566