Description:

Reports on the Microsoft Secure Score improvement action Set the phishing email level threshold at 2 or higher, part of Microsoft Defender for Office 365. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.

Why:

The threshold controls the sensitivity with which machine learning models are applied to email messages to determine whether a phishing attempt has occurred. A higher value indicates greater sensitivity. The default value is 1, but 2 or 3 are the recommended values.

Configured: 100% of users are affected by policies that are configured securely

Not Configured: One or more applicable policies are not configured securely.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Exchange

Microsoft Licensing: M365 Defender

Secure Score Impact: YES — Microsoft Secure Score control mdo_phishthresholdlevel.

Remediation in Augmentt: Microsoft Defender portal

Compliance Frameworks:

  • NIST CSF 2.0 — DE.CM-09

  • CIS Microsoft 365 Benchmark v5 — 2.1.7

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 2.1.7

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 2.1.7

  • CIS Controls v8 — 9.7

  • CIS Controls v8.1 — 9.7

  • CIS Controls v7 — 7

  • HIPAA Security Rule — 164.308(a)(5)(ii)(B)

Microsoft documentation: