M365EXO-037: Mailbox auditing enabled organization-wide (MS.EXO.13.1)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Visibility & Analytics (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.13.1 requires that mailbox auditing be enabled. Mailbox auditing records actions taken on mailbox contents by owners, delegates, and administrators, providing essential forensic evidence for investigating compromise. Although enabled by default, this control guards against inadvertent or malicious disabling at the organization level.
Recommended value
Organization AuditDisabled = False so mailbox auditing is enabled tenant-wide
Remediation
Verify that mailbox auditing is enabled organization-wide by confirming AuditDisabled is False on the organization configuration. If auditing is disabled, re-enable it and investigate why it was turned off to rule out tampering. Confirm the default audited actions cover MailItemsAccessed, Send, SoftDelete, and HardDelete across logon types.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.EXO.13.1v1
- NIST SP 800-53
- AU-2, AU-3
- MITRE ATT&CK
- T1114