Description:
Verifies that the Default connection filter policy has an empty IP allow list. Addresses on the allow list bypass spam filtering and sender authentication checks (SPF, DKIM and DMARC).
Why:
The IP allow list on the Default connection filter policy bypasses spam filtering and sender authentication checks (SPF, DKIM, DMARC) for the listed IP addresses. The recommended state is an empty IP allow list, which ensures all messages are subject to full anti-spam and sender authentication checks regardless of origin.
Configured: The Default connection filter policy has an empty IP allow list.
Not Configured: The Default connection filter policy has one or more entries in the IP allow list.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
CIS Microsoft 365 Benchmark v6 (Level 1) — 2.1.12
CIS Microsoft 365 Benchmark v7 (Level 1) — 2.1.12
CIS Controls v8 — 9.7
CIS Controls v8.1 — 9.7
Microsoft documentation:
