Description:

Monitors for Shared Mailboxes that do not have logins disabled.

Why:

It is best practice to block sign-in on shared mailbox accounts, as recommended by Microsoft, to avoid an attacker from being able to authenticate and login to such accounts.

Status detail shown in Augmentt: You have N of M shared mailboxes that have sign-ins blocked

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: General

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.AA-01

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 1.2.2

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 1.2.2

  • HIPAA Security Rule — 164.308(a)(3)(ii)(C), 164.312(a)(1)

  • CMMC Level 1 — IA.L1-b.1.v

  • CMMC Level 2 — IA.L2-3.5.1, IA.L2-3.5.2

Microsoft documentation:


_KB status: already published as "Block Sign-in on Shared Mailboxes" — update the existing step in place._

_Source: Augmentt native check. Check ID blocksigninsharedmailboxes (module 19)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · General · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · HIPAA · CMMC Level 1 · CMMC Level 2