Description:

Verifies that external sender warnings are configured.

Why:

Phishing is an ever-present threat. Alerting users when email originates from outside their organization can encourage them to exercise increased caution, especially if an email is one they expected from an internal sender. This check verifies that either the native Exchange External Message setting is enabled, or that the text [External] is prepended to the subject line using a transport rule.

Configured: External sender warnings are configured.

Not Configured: External sender warnings are not configured.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Exchange

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks:

  • CISA SCuBA — MS.EXO.7.1

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 6.2.3

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 6.2.3

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID CISA.MS.EXO.7.1 (module 1019)._

Sourced for this page:

  • Category — Maester test catalog (maester.dev/docs/tests) — test is graded against the "exchange" tier, so it evaluates a Microsoft Entra ID setting

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · M365 Basic · CISA SCuBA · CIS M365 v6 L1 · CIS M365 v7 L1