Description:

Verifies that Direct Send is rejected in Exchange Online. Direct Send lets on-premises applications, printers and other devices deliver mail to the tenant's hosted mailboxes over SMTP without authenticating. The check is compliant when the organization's RejectDirectSend setting is enabled.

Why:

Direct Send allows internal applications and devices to send email using an SMTP relay through Exchange Online without authenticating. Rejecting Direct Send prevents unauthorized or misconfigured devices from sending emails through your Exchange Online environment, reducing the risk of spoofing and unauthorized mail flow.

Configured: Feature is in place.

Not Configured: Feature is not in place.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Exchange

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.DS-02

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 6.5.5

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 6.5.5

  • HIPAA Security Rule — 164.312(e)(2)(i)

  • CMMC Level 1 — SC.L1-b.1.x

  • CMMC Level 2 — SC.L2-3.13.1

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Augmentt native check. Check ID rejectDirectSend (module 500)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · Exchange · M365 Basic · CIS M365 v6 L2 · CIS M365 v7 L2 · NIST CSF 2.0 · HIPAA · CMMC Level 1 · CMMC Level 2