M365EXO-040: No allowed domains in anti-spam policy (MS.EXO.14.3)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.14.3 requires that allowed domains not be added to inbound anti-spam policies. Allowing an entire domain lets every sender at that domain bypass spam protections, and common domains can be spoofed to abuse the exception. Allowed individual senders are acceptable, but domain-wide allow entries create a broad bypass.

Recommended value

AllowedSenderDomains empty on all anti-spam (hosted content filter) policies

Remediation

Review every anti-spam policy and remove all entries from the allowed sender domains list. Where false positives must be addressed, add specific allowed senders rather than whole domains. Confirm no custom anti-spam policy reintroduces an allowed-domain entry, especially for common domains.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-040
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-8
MITRE ATT&CK
T1566