Skip to main content
Version: 2.1.1-preview

CISA.MS.EXO.15.1 - URL comparison with a block-list SHOULD be enabled.

Overview​

URL comparison with a block-list SHOULD be enabled.

Rationale: Users may be directed to malicious websites via links in email. Blocking access to known, malicious URLs can prevent users from accessing known malicious websites.

Remediation action:​

  1. Sign in to Microsoft 365 Defender.
  2. In the left-hand menu, go to Email & Collaboration > Policies & Rules.
  3. Select Threat Policies.
  4. From the Templated policies section, select Preset Security Policies.
  5. Under either Standard protection or Strict protection, select Manage protection settings.
  6. Select Next until you reach the Apply Defender for Office 365 protection page.
  7. On the Apply Defender for Office 365 protection page, select All recipients.
  8. (Optional) Under Exclude these recipients, add Users and Groups to be exempted from the preset policies.
  9. Select Next on each page until the Review and confirm your changes page.
  10. On the Review and confirm your changes page, select Confirm.

Test Metadata​

FieldValue
Test IDCISA.MS.EXO.15.1
SeverityMedium
SuiteCISA
Categoryexchange
PowerShell testTest-MtCisaSafeLink
TagsCISA, CISA.MS.EXO.15.1, MS.EXO, MS.EXO.15.1

Source​

  • Pester test: tests/cisa/exchange/Test-MtCisaSafeLink.Tests.ps1
  • PowerShell source: powershell/public/cisa/exchange/Test-MtCisaSafeLink.ps1