M365EXO-042: Direct download links scanned for malware (MS.EXO.15.2)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.15.2 recommends that direct download links be scanned for malware. Links in mail may point directly to malware downloads. Real-time scanning of the destination file when a user clicks a direct download link blocks the download if malware is detected, preventing device infection.
Recommended value
Safe Links (or comparable) policy with real-time URL/file scanning enabled (ScanUrls = True)
Remediation
Enable real-time scanning of URLs and direct-download destinations in the Safe Links or comparable policy so files behind links are scanned for malware at click time. Apply the policy to all users. Verify the option to deliver only after scanning completes is configured where appropriate to maximize protection.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Framework mappings
- NIST SP 800-53
- SI-3
- MITRE ATT&CK
- T1566.002