Description:
Reports on the Microsoft Secure Score improvement action Ensure that an anti-phishing policy has been created, part of Exchange Online Protection. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.
Why:
By default, Office 365 includes built-in features that help protect users from phishing attacks. Set up anti-phishing polices to increase this protection, for example by refining settings to better detect and prevent impersonation and spoofing attacks. The default policy applies to all users within the organization, and is a single view to fine-tune anti-phishing protection. Custom policies can be created and configured for specific users, groups or domains within the organization and will take precedence over the default policy for the scoped users.
Configured: 100% of users are affected by policies that are configured securely
Not Configured: One or more applicable policies are not configured securely.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: M365 Defender
Secure Score Impact: YES — Microsoft Secure Score control mdo_antiphishingpolicies.
Remediation in Augmentt: Microsoft Defender portal
Compliance Frameworks:
NIST CSF 2.0 — DE.CM-09
CIS Microsoft 365 Benchmark v5 — 2.1.7
CIS Microsoft 365 Benchmark v6 (Level 2) — 2.1.7
CIS Microsoft 365 Benchmark v7 (Level 2) — 2.1.7
CIS Controls v8 — 9.7
CIS Controls v8.1 — 9.7
CIS Controls v7 — 7
HIPAA Security Rule — 164.308(a)(5)(ii)(B)
CMMC Level 1 — SI.L1-b.1.xiii
CMMC Level 2 — SI.L2-3.14.2
Microsoft documentation:
