M365EXO-043: User click tracking enabled (MS.EXO.15.3)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.15.3 recommends that user click tracking be enabled. Click tracking records when users click links in mail, providing after-the-fact visibility into whether a malicious link may have been visited. This is essential for scoping and responding to incidents involving phishing links.

Recommended value

Safe Links (or comparable) policy with click tracking enabled (DoNotTrackUserClicks = False)

Remediation

Ensure user click tracking is enabled in the Safe Links or comparable policy so that clicks on links in mail are recorded (the do-not-track option should be off). Apply the policy to all users. Confirm click telemetry is available in the relevant reporting surface for incident investigation.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-043
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
AU-2, SI-4
MITRE ATT&CK
T1566.002