M365EXO-042: Direct download links scanned for malware (MS.EXO.15.2)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.15.2 recommends that direct download links be scanned for malware. Links in mail may point directly to malware downloads. Real-time scanning of the destination file when a user clicks a direct download link blocks the download if malware is detected, preventing device infection.

Recommended value

Safe Links (or comparable) policy with real-time URL/file scanning enabled (ScanUrls = True)

Remediation

Enable real-time scanning of URLs and direct-download destinations in the Safe Links or comparable policy so files behind links are scanned for malware at click time. Apply the policy to all users. Verify the option to deliver only after scanning completes is configured where appropriate to maximize protection.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-042
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-3
MITRE ATT&CK
T1566.002