M365EXO-018: DMARC enforcement set to p=reject (MS.EXO.4.2)
- Plataforma
- Entra ID / M365
- Categoría
- Advanced Threat Protection
- Severidad
- High
- Pilar de Zero Trust
- Applications & Workloads (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA MS.EXO.4.2 requires that the DMARC message rejection option be set to p=reject. Of the three policy values (none, quarantine, reject), reject provides the strongest protection by instructing receivers to drop unauthenticated mail outright. A policy of none or quarantine leaves a window for spoofed mail to reach or land near user inboxes.
Valor recomendado
DMARC record for each domain contains p=reject
Remediación
After confirming that all legitimate senders pass SPF or DKIM alignment under monitoring, update each domain's DMARC record to p=reject so receivers discard mail that fails authentication. Move through p=none and p=quarantine first to avoid disrupting legitimate mail. Continue monitoring aggregate reports after enforcing reject to catch any newly onboarded sender that is not yet aligned.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- MS.EXO.4.2v1
- NIST SP 800-53
- SI-8
- MITRE ATT&CK
- T1566.001