Description:
Verifies that external sender warnings are configured.
Why:
Phishing is an ever-present threat. Alerting users when email originates from outside their organization can encourage them to exercise increased caution, especially if an email is one they expected from an internal sender. This check verifies that either the native Exchange External Message setting is enabled, or that the text [External] is prepended to the subject line using a transport rule.
Configured: External sender warnings are configured.
Not Configured: External sender warnings are not configured.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Exchange
Microsoft Licensing: Works with Basic licensing
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
CISA SCuBA — MS.EXO.7.1
CIS Microsoft 365 Benchmark v6 (Level 1) — 6.2.3
CIS Microsoft 365 Benchmark v7 (Level 1) — 6.2.3
Microsoft documentation:
