Description:

Reports on the Microsoft Secure Score improvement action Move messages that are detected as impersonated users by mailbox intelligence, part of Microsoft Defender for Office 365. Microsoft evaluates this control across your tenant's policies and Augmentt surfaces the result alongside your other posture checks.

Why:

This setting specifies what to do with messages for impersonation detections from mailbox intelligence results.

If a message is detected to be an impersonated user by mailbox intelligence, no action will be applied by default. We recommend moving the message to the recipients’ junk email folder and strongly recommend quarantining it.

Configured: 100% of users are affected by policies that are configured securely

Not Configured: One or more applicable policies are not configured securely.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Exchange

Microsoft Licensing: M365 Defender

Secure Score Impact: YES — Microsoft Secure Score control mdo_mailboxintelligenceprotectionaction.

Remediation in Augmentt: Microsoft Defender portal

Compliance Frameworks:

  • NIST CSF 2.0 — DE.CM-09

  • CIS Microsoft 365 Benchmark v5 — 2.1.7

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 2.1.7

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 2.1.7

  • CIS Controls v8 — 9.7

  • CIS Controls v8.1 — 9.7

  • CIS Controls v7 — 7

  • HIPAA Security Rule — 164.308(a)(5)(ii)(B)

Microsoft documentation: