M365EXO-045: Alerts routed to monitored destination (MS.EXO.16.2)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Visibility & Analytics (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.16.2 recommends that alerts be sent to a monitored address or incorporated into a SIEM. An alert that fires but is delivered nowhere monitored is not actionable, allowing suspicious events to go unaddressed and increasing incident impact. Each required alert policy should notify a monitored recipient or feed a SIEM.
Recommended value
Each enabled alert policy has notification recipients set to a monitored mailbox or is ingested by a SIEM
Remediation
Configure each enabled alert policy with one or more notification recipients that point to a monitored mailbox or distribution list, or forward alerts into a SIEM. Confirm the destination is actively monitored so alerts are triaged promptly. Where a third-party alerting solution is used, verify its alerts reach the same monitored destination or SIEM.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.DEFENDER.5.2v1
- NIST SP 800-53
- SI-4, IR-4, AU-6
- MITRE ATT&CK
- T1114.003