Description:
Verifies that calendar details are not shared with all domains.
Why:
Calendar details may contain information that should not be shared by default with all domains. Disabling sharing with all domains closes an avenue for data exfiltration while still allowing for legitimate use as needed.
Configured: Calendar details are not shared with all domains.
Not Configured: Calendar details are shared with all domains.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft Secure Score control exo_individualsharing.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CISA SCuBA — MS.EXO.6.2
CIS Microsoft 365 Benchmark v6 (Level 1) — 1.3.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 1.3.1
Microsoft documentation:
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID CISA.MS.EXO.6.2 (module 1020)._
Sourced for this page:
Category — Maester test catalog (maester.dev/docs/tests) — test is graded against the "exchange" tier, so it evaluates a Microsoft Entra ID setting
Secure Score — Microsoft Secure Score control read by Augmentt from Microsoft Graph
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · CISA SCuBA
