M365EXO-040: No allowed domains in anti-spam policy (MS.EXO.14.3)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.14.3 requires that allowed domains not be added to inbound anti-spam policies. Allowing an entire domain lets every sender at that domain bypass spam protections, and common domains can be spoofed to abuse the exception. Allowed individual senders are acceptable, but domain-wide allow entries create a broad bypass.
Recommended value
AllowedSenderDomains empty on all anti-spam (hosted content filter) policies
Remediation
Review every anti-spam policy and remove all entries from the allowed sender domains list. Where false positives must be addressed, add specific allowed senders rather than whole domains. Confirm no custom anti-spam policy reintroduces an allowed-domain entry, especially for common domains.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- NIST SP 800-53
- SI-8
- MITRE ATT&CK
- T1566