M365EXO-037: Mailbox auditing enabled organization-wide (MS.EXO.13.1)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Visibility & Analytics (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.13.1 requires that mailbox auditing be enabled. Mailbox auditing records actions taken on mailbox contents by owners, delegates, and administrators, providing essential forensic evidence for investigating compromise. Although enabled by default, this control guards against inadvertent or malicious disabling at the organization level.

Recommended value

Organization AuditDisabled = False so mailbox auditing is enabled tenant-wide

Remediation

Verify that mailbox auditing is enabled organization-wide by confirming AuditDisabled is False on the organization configuration. If auditing is disabled, re-enable it and investigate why it was turned off to rule out tampering. Confirm the default audited actions cover MailItemsAccessed, Send, SoftDelete, and HardDelete across logon types.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-037
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.EXO.13.1v1
NIST SP 800-53
AU-2, AU-3
MITRE ATT&CK
T1114