Description:
This check verifies that the native Exchange External Message setting is enabled in Exchange by ensuring that Set-ExternalInOutlook -Enabled is true.
The tag serves several purposes:
Security Awareness: The tag alerts users that an email originated from an external sender (someone outside the organization). It encourages caution and prompts recipients to double-check the email's legitimacy. Even with robust spam filters, user awareness remains essential in preventing spyware and malicious links.
Phishing Prevention: Despite measures like SPF, DKIM, and DMARC, some phishing and spam emails can still slip through. The external tag helps users identify potentially harmful messages and avoid clicking on suspicious links or attachments.
Visual Cue: When an email bears the "External" tag, it stands out visually. Users can quickly recognize that the sender is not part of their organization, prompting them to exercise caution.
Admin Tracking: For administrators, external tags assist in tracking and monitoring potentially risky emails. It helps identify patterns and assess security threats.
Why:
This check verifies that the native Exchange External Message setting is enabled in Exchange by ensuring that 'Set-ExternalInOutlook - Enabled' is true. This allows users to easily differentiate phishing messages originating from an external source. If your organization already uses mail flow rules (also known as transport rules) to add text to the subject line of messages from external senders, you should disable those rules before you enable this feature to avoid duplication.
Configured: This setting is in place.
Not Configured: This setting is not in place.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: General
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
CISA SCuBA — MS.EXO.7.1
NIST CSF 2.0 — DE.CM-03
CIS Microsoft 365 Benchmark v6 (Level 1) — 6.2.3
CIS Microsoft 365 Benchmark v7 (Level 1) — 6.2.3
CMMC Level 1 — SC.L1-b.1.x
CMMC Level 2 — SC.L2-3.13.1
Microsoft documentation:
IMPORTANT:
After this setting is enabled, it can take between 24 and 48 hours for users to see the External icon in messages from external senders in supported versions of Outlook. If you decide to revert this setting, Exchange will also take 24 to 48 hours to stop tagging email messages from external senders, and any emails already tagged will not have their tags removed.
Source: Set-ExternalInOutlook (ExchangePowerShell)
_KB status: already published as "Exchange External Sender Tag" — update the existing step in place._
_Source: Augmentt native check. Check ID externalMailTag (module 21)._
Sourced for this page:
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · General · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · CISA SCuBA · CMMC Level 1 · CMMC Level 2
