Description:
Reports on the Microsoft Secure Score improvement action Enable impersonated user protection, part of Microsoft Defender for Office 365. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.
Why:
Prevents specified internal or external email addresses from being impersonated as message senders in phishing attempts. By default, impersonated user protection is disabled, and no sender email addresses are covered by impersonation protection, whether in the default policy or in custom policies.
Configured: 100% of users are affected by policies that are configured securely
Not Configured: One or more applicable policies are not configured securely.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: M365 Defender
Secure Score Impact: YES — Microsoft Secure Score control mdo_targetedusersprotection.
Remediation in Augmentt: Microsoft Defender portal
Compliance Frameworks:
CISA SCuBA — MS.DEFENDER.2.1, MS.EXO.11.1
NIST CSF 2.0 — DE.CM-09
CIS Microsoft 365 Benchmark v6 (Level 2) — 2.1.7
CIS Microsoft 365 Benchmark v7 (Level 2) — 2.1.7
HIPAA Security Rule — 164.308(a)(5)(ii)(B)
Microsoft documentation:
