Description:
Verifies that the Default connection filter policy has the safe list turned off. The safe list is a dynamically maintained Microsoft allow list whose contents administrators cannot inspect.
Why:
Connection filtering identifies known-good and known-bad source email servers by IP. The safe list is a pre-configured allow list that Microsoft updates dynamically; administrators have no visibility into which senders it includes. Email from servers on the safe list skips spam filtering and sender authentication (SPF, DKIM, DMARC) checks entirely. Turning the safe list on creates a black-box bypass of the rest of the anti-spam stack.
Configured: The Default connection filter policy has the safe list turned off.
Not Configured: The Default connection filter policy has the safe list turned on.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CIS Microsoft 365 Benchmark v6 (Level 1) — 2.1.13
CIS Microsoft 365 Benchmark v7 (Level 1) — 2.1.13
CIS Controls v8 — 9.7
CIS Controls v8.1 — 9.7
Microsoft documentation:
