Description:

Reports on the Microsoft Secure Score improvement action Ensure all forms of mail forwarding are blocked and/or disabled, part of Exchange Online Protection. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.

Why:

Attackers often create these rules to exfiltrate data from your tenancy, this could be accomplished via access to an end-user account or otherwise. An insider could also use one of these methods as an secondary channel to exfiltrate sensitive data.

Configured: 100% of users are affected by policies that are configured securely

Not Configured: One or more applicable policies are not configured securely.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Exchange

Microsoft Licensing: M365 Defender

Secure Score Impact: YES — Microsoft Secure Score control mdo_blockmailforward.

Remediation in Augmentt: Microsoft Defender portal

Compliance Frameworks:

  • NIST CSF 2.0 — PR.DS-02

  • CIS Microsoft 365 Benchmark v5 — 6.2.1

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 6.2.1

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 6.2.1

  • CIS Controls v8 — 0

  • CIS Controls v8.1 — 0

Microsoft documentation: