M365EXO-045: Alerts routed to monitored destination (MS.EXO.16.2)
- Plataforma
- Entra ID / M365
- Categoría
- Advanced Threat Protection
- Severidad
- Medium
- Pilar de Zero Trust
- Visibility & Analytics (peso 1)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA MS.EXO.16.2 recommends that alerts be sent to a monitored address or incorporated into a SIEM. An alert that fires but is delivered nowhere monitored is not actionable, allowing suspicious events to go unaddressed and increasing incident impact. Each required alert policy should notify a monitored recipient or feed a SIEM.
Valor recomendado
Each enabled alert policy has notification recipients set to a monitored mailbox or is ingested by a SIEM
Remediación
Configure each enabled alert policy with one or more notification recipients that point to a monitored mailbox or distribution list, or forward alerts into a SIEM. Confirm the destination is actively monitored so alerts are triaged promptly. Where a third-party alerting solution is used, verify its alerts reach the same monitored destination or SIEM.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- MS.DEFENDER.5.2v1
- NIST SP 800-53
- SI-4, IR-4, AU-6
- MITRE ATT&CK
- T1114.003