Auditing - Ensure The Spoofed Domains Report Is Reviewed Weekly

 








Summary

Spoof intelligence present in the Security Center should be used on the Anti-spam settings page in order to review all senders, who are spoofing either domains that are part of an organization, or spoofing external domains. Spoof intelligence is available as a part of Office 365 Enterprise E5 or separately as part of Defender for Office 365 and as of October, 2018 Exchange Online Protection (EOP).

Reason

Malicious actors generally spoof domains to trick users into conducting actions they normally would not or should not, via phishing emails. Running this report will inform the message administrators of current activities, and the phishing techniques used by bad actors . This information can also be used to inform end users and plan against future campaigns. 

How to?

To review the report, use the Microsoft 365 Admin center:
  1. Go to Security.
  2. Under Email & collaboration click on Policies & rules then select Threat policies.
  3. Under Rules click on Tenant Allow / Block Lists then select Spoofing.
  4. Review.

To view spoofed senders that were allowed or blocked by spoof intelligence using the Exchange Online PowerShell Module:
  1. Connect to Exchange Online using Connect-ExchangeOnline.
  2. Now, run the following Exchange Online PowerShell command: 

  3. Get-SpoofIntelligenceInsight

      3. Review 

Monitor:

To verify the report is being reviewed at least weekly, confirm that the necessary procedures are in place and being followed.













































Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements