Description:
Reports on the Microsoft Secure Score improvement action Don't add allowed IP addresses in the connection filter policy, part of Exchange Online Protection. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.
Why:
The available safe sender lists are described in the following list in order from most recommended to least recommended:
Mail flow rules
Outlook Safe Senders
IP Allow List (connection filtering)
Allowed sender lists or allowed domain lists (anti-spam policies)
Without additional verification like mail flow rules, email from sources in the IP Allow List skips spam filtering and sender authentication (SPF, DKIM, DMARC) checks. Since the IP Allow List doesn't prevent malware or high confidence phishing messages from being filtered, this creates a high risk of attackers successfully delivering email to an inbox that would otherwise be filtered.
Configured: The allowed IP addresses list in the connection filter policy is empty
Not Configured: One or more applicable policies are not configured securely.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: M365 Defender
Secure Score Impact: YES — Microsoft Secure Score control mdo_connectionfilter.
Remediation in Augmentt: Microsoft Defender portal
Compliance Frameworks:
CISA SCuBA — MS.EXO.12.2
NIST CSF 2.0 — DE.CM-01
CIS Microsoft 365 Benchmark v6 (Level 1) — 2.1.12
CIS Microsoft 365 Benchmark v7 (Level 1) — 2.1.12
CIS Controls v8 — 9.7
CIS Controls v8.1 — 9.7
CISA M365 v5 — 2.1.12
Microsoft documentation:
