Description:
Reports on the Microsoft Secure Score improvement action Set maximum number of internal recipients that a user can send to within an hour, part of Exchange Online Protection. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.
Why:
Configure the maximum number of recipients that a user can send to per hour for internal recipients. After an account is compromised, attackers commonly use the account to generate spam and phish. Configuring recommended values can reduce the amount of spam and phishing emails, while also allowing you to be notified when these thresholds have been reached.
Configured: 100% of users are affected by policies that are configured securely
Not Configured: One or more applicable policies are not configured securely.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: M365 Defender
Secure Score Impact: YES — Microsoft Secure Score control mdo_recipientinternallimitperhour.
Remediation in Augmentt: Microsoft Defender portal
Compliance Frameworks:
NIST CSF 2.0 — RS.MI-01
CIS Microsoft 365 Benchmark v6 (Level 1) — 2.1.15
CIS Microsoft 365 Benchmark v7 (Level 1) — 2.1.15
Microsoft documentation:
