Description:
Verifies that internal phishing protection for Microsoft Forms is enabled, so Microsoft's built-in scanner blocks suspicious forms that attempt to collect credentials or personal information.
Why:
Microsoft Forms can be used to collect credentials and personal information with little friction. Enabling Microsoft's built-in phishing scanner blocks suspicious forms and response collection until the triggering content is reviewed or removed.
Configured: Internal phishing protection for Forms is enabled.
Not Configured: Internal phishing protection for Forms is disabled.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: General
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft publishes the improvement action "Ensure internal phishing protection for Forms is enabled".
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CIS Microsoft 365 Benchmark v6 (Level 1) — 1.3.5
CIS Controls v8 — 10.1, 14.2
Microsoft documentation:
