M365EXO-045: Alerts routed to monitored destination (MS.EXO.16.2)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Visibility & Analytics (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.16.2 recommends that alerts be sent to a monitored address or incorporated into a SIEM. An alert that fires but is delivered nowhere monitored is not actionable, allowing suspicious events to go unaddressed and increasing incident impact. Each required alert policy should notify a monitored recipient or feed a SIEM.

Recommended value

Each enabled alert policy has notification recipients set to a monitored mailbox or is ingested by a SIEM

Remediation

Configure each enabled alert policy with one or more notification recipients that point to a monitored mailbox or distribution list, or forward alerts into a SIEM. Confirm the destination is actively monitored so alerts are triaged promptly. Where a third-party alerting solution is used, verify its alerts reach the same monitored destination or SIEM.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-045
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.DEFENDER.5.2v1
NIST SP 800-53
SI-4, IR-4, AU-6
MITRE ATT&CK
T1114.003