Description:
Reports on the Microsoft Secure Score improvement action Ensure all forms of mail forwarding are blocked and/or disabled, part of Exchange Online Protection. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.
Why:
Attackers often create these rules to exfiltrate data from your tenancy, this could be accomplished via access to an end-user account or otherwise. An insider could also use one of these methods as an secondary channel to exfiltrate sensitive data.
Configured: 100% of users are affected by policies that are configured securely
Not Configured: One or more applicable policies are not configured securely.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: M365 Defender
Secure Score Impact: YES — Microsoft Secure Score control mdo_blockmailforward.
Remediation in Augmentt: Microsoft Defender portal
Compliance Frameworks:
NIST CSF 2.0 — PR.DS-02
CIS Microsoft 365 Benchmark v5 — 6.2.1
CIS Microsoft 365 Benchmark v6 (Level 1) — 6.2.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 6.2.1
CIS Controls v8 — 0
CIS Controls v8.1 — 0
Microsoft documentation:
