Skip to main content

MAL — Email & Threat Protection

Email authentication and malware protections. 64 controls in total — 63 automatic, 1 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
MAL-01 SPF record (all domains)
L1
Checks whether your email is protected against spoofed sending in your name, across all domains.✅ Valid on all domains · ❌ Any missingAuto
N/A if no data
MAL-02 DMARC record (all domains)
L1
Checks whether spoofed email is blocked by completing SPF/DKIM validation, across all domains.✅ Valid on all domains · ❌ Any missingAuto
N/A if no data
MAL-03 Automatic email forwarding block
L1
Checks whether incoming email is auto-forwarded outside the organization. It prevents data leakage.✅ Forwarding off · ⚠️ On up to 5 mailboxes, no rule, auto-forward off · ❌ More than thatAuto
N/A if no data
MAL-04 Legacy SMTP authentication disabled
L1
Checks the open door that legacy email protocols leave to brute-force and spam attacks.✅ Off for everyone · ⚠️ On for up to 5 users · ❌ On for more than 5 usersAuto
N/A if no data
MAL-07 Meeting lobby (organization only)
L1
Checks whether outside people can join meetings directly without passing through the lobby.✅ Organization only can join · ❌ Outsiders can join tooAuto
N/A if no data
MAL-09 Outbound email spam filter
L1
Checks the filter that stops a compromised account from sending spam outside.✅ Configured · ❌ Not configuredAuto
N/A if no data
MAL-10 Safe Attachments policy
L1
Checks whether malicious email attachments are scanned and blocked.✅ Enabled · ❌ DisabledAuto
Requires Microsoft 365 E3; N/A without Global Reader or data
MAL-11 Safe Links policy
L1
Checks whether clicks on malicious links in email are blocked.✅ Enabled · ❌ DisabledAuto
Requires Microsoft 365 E3; N/A without Global Reader or data
MAL-12 DKIM signing (all domains)
L1
Checks the digital signature against email forgery across all domains.✅ Configured on all domains · ❌ Any missingAuto
N/A if no data
MAL-13 Impersonation protection
L1
Checks the protection against phishing attacks that impersonate senior executives.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-15 Modern authentication (Exchange)
L1
Checks the modern authentication that stops legacy auth from bypassing multi-step verification.✅ Enabled · ❌ DisabledAuto
N/A if no data
MAL-16 Mailbox audit logging
L1
Checks whether mailbox access is logged. It makes breach detection possible.✅ On · ❌ OffAuto
N/A if no data
MAL-17 Dangerous file extension filter
L1
Blocks harmful file extensions from arriving by email and being run by mistake. It lowers ransomware risk.✅ Enabled · ❌ DisabledAuto
N/A if no data
MAL-18 Safe Attachments (unknown threat analysis)
L2
Checks whether unknown malware is analyzed in an isolated environment.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P1; N/A without Global Reader or data
MAL-19 Safe Attachments (SharePoint/OneDrive/Teams)
L2
Checks whether malicious files shared in SharePoint, OneDrive and Teams are scanned.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P1; N/A without Global Reader or data
MAL-20 Outbound spam admin notification
L1
Checks whether the admin is alerted if a compromised account starts sending spam outside.✅ Notification on · ❌ OffAuto
N/A if no data
MAL-21 Extended file extension filter
L2
Checks whether rare dangerous extensions beyond the default list are also blocked.✅ Extended list applied · ❌ Default only / incompleteAuto
N/A if no data
MAL-22 No IP allow list in the connection filter
L1
Stops IPs on an allow list from bypassing spam and phishing checks.✅ Allow list empty · ❌ IP allow list definedAuto
N/A if no data
MAL-23 Connection filter safe list disabled
L1
Stops an unmanaged whitelist from bypassing the security scan.✅ Off · ❌ OnAuto
N/A if no data
MAL-24 No allowed sender domain list on inbound email
L1
Stops allowed sender domains from bypassing spam and phishing checks.✅ No allowed domain · ❌ Allowed domain definedAuto
N/A if no data
MAL-25 Outbound email message limits
L1
Checks the limits that cap bulk spam sending from a compromised account.✅ Limits configured · ❌ Not configuredAuto
N/A if no data
MAL-26 Break-glass account monitoring
L1
Checks whether use of emergency admin accounts is monitored.Attested
Customer attestation (not measured automatically)
MAL-27 Priority account protection
L1
Checks the protection against targeted phishing (whaling) aimed at senior executives.✅ Priority account protection on · ❌ OffAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-28 Strict protection profile for priority accounts
L1
Checks whether Microsoft's strictest security profile is applied to priority accounts.✅ Strict protection applied · ❌ Not appliedAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-30 Automatic threat purge for Teams (ZAP)
L1
Checks whether links later found malicious in Teams messages are removed automatically.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-31 Mailbox audit bypass disabled
L1
Checks that no mailbox bypasses the audit log.✅ No mailbox bypasses auditing · ❌ A mailbox has bypass onAuto
N/A if no data
MAL-32 Transport rules add no domain whitelist
L1
Checks that transport rules do not bypass the spam filter for specific domains.✅ No filter-bypassing rule · ❌ A filter-bypassing rule existsAuto
N/A if no data
MAL-33 External sender tagging
L1
Checks whether email from outside is visually tagged. It makes spoofed email easier to spot.✅ Tagging on · ❌ OffAuto
N/A if no data
MAL-34 MailTips warnings (end users)
L1
Checks whether critical warnings, such as an external recipient or a large distribution group, are shown to the user.✅ On · ❌ OffAuto
N/A if no data
MAL-35 Restricting extra cloud storage in Outlook on the web
L2
Checks whether third-party cloud storage links (Dropbox, Google Drive and the like) are restricted in Outlook on the web.✅ Restricted · ❌ Left openAuto
N/A if no data
MAL-36 Direct Send submissions rejected
L2
Stops mail sent by connecting directly from outside and appearing to come from inside.✅ Rejected · ❌ AllowedAuto
N/A if no data
MAL-37 Anonymous meeting join disabled
L2
Checks whether unverified anonymous users are blocked from joining Teams meetings; anonymous access can let unauthorized people into a meeting.✅ Anonymous join off · ❌ OnAuto
N/A if no data
MAL-38 Anonymous/dial-in meeting start disabled
L1
Checks whether anonymous or dial-in users are blocked from starting a meeting with no host present; an early start weakens meeting control.✅ Anonymous/dial-in start off · ❌ OnAuto
N/A if no data
MAL-39 Dial-in users cannot bypass the lobby
L1
Checks whether dial-in (PSTN) callers are prevented from joining a meeting directly without passing through the lobby.✅ Dial-in cannot bypass lobby · ❌ Can bypassAuto
N/A if no data
MAL-40 Anonymous users blocked from meeting chat
L2
Checks whether anonymous users are blocked from reading and writing in the meeting chat; anonymous chat access carries abuse and link-sharing risk.✅ Meeting chat excludes anonymous or is off · ❌ Anonymous can chat tooAuto
N/A if no data
MAL-41 Only organizers/co-organizers can present
L2
Checks whether only organizers and co-organizers can present in a meeting; letting everyone present opens the door to screen and content abuse.✅ Only organizers/co-organizers can present · ❌ Everyone can presentAuto
N/A if no data
MAL-42 External participants cannot request/give control
L1
Checks whether external participants are blocked from requesting or being given presentation control; handing over control grants an outsider authority over the screen.✅ External participants cannot give/request control · ❌ Can request and receive itAuto
N/A if no data
MAL-43 External (untrusted) meeting chat disabled
L2
Checks whether meeting chat with untrusted external organizations is turned off; untrusted external chat is a vector for malicious links and file delivery.✅ Untrusted external meeting chat off · ❌ OnAuto
N/A if no data
MAL-44 Meeting recording off by default
L2
Checks whether cloud recording is off by default in the global meeting policy; letting anyone record can lead to sensitive conversations being stored without consent.✅ Meeting recording off · ❌ OnAuto
N/A if no data
MAL-45 Third-party file storage disabled
L2
Checks whether third-party storage providers such as Dropbox, Box, Google Drive, ShareFile and Egnyte are turned off in Teams; unapproved cloud storage carries data-leakage risk.✅ No third-party storage provider enabled · ❌ At least one enabledAuto
N/A if no data
MAL-46 Email into channel disabled
L2
Checks whether sending email directly into a Teams channel is turned off; email-into-channel lets unfiltered external content land in a channel.✅ Email into channel off · ❌ OnAuto
N/A if no data
MAL-47 Consumer Teams federation disabled
L1
Checks whether communication with personal (consumer) Teams accounts is turned off; contact with unmanaged personal accounts is a vector for data leakage and social engineering.✅ Personal Teams federation off · ❌ OnAuto
N/A if no data
MAL-48 Inbound consumer Teams invites disabled
L1
Checks whether personal Teams accounts are blocked from initiating first contact with the organization; inbound personal invites open first contact from unmanaged accounts.✅ Inbound personal Teams invites off · ❌ OnAuto
N/A if no data
MAL-49 Trial tenant external access blocked
L2
Checks whether external access with unverified trial tenants is blocked; trial tenants are short-lived and prone to abuse.✅ Trial tenant external access blocked · ❌ AllowedAuto
N/A if no data
MAL-50 Federation limited to authorized domains
L1
Checks whether Teams federation is off or limited to an allow-list of authorized domains; federation open to all external domains is a broad attack surface.✅ Federation off or limited to authorized domains · ❌ Open to all known domainsAuto
N/A if no data
MAL-51 User security reports stay in-house
L1
Checks whether users can report suspicious messages in Teams and whether those reports go to the organization's own mailbox rather than to Microsoft; reports that do not stay in-house reduce the internal security team's visibility.✅ Teams end-user reporting on and reports routed to the organization mailbox · ❌ Reporting off or reports not routed in-houseAuto
Requires E5; N/A without Global Reader or data
MAL-52 Admin notification on internal malware sending
L1
Checks whether an admin is notified when an internal user sends malware (in the default anti-malware policy); without notification, an internally sourced infection is noticed late.✅ Internal sender admin notification on with an address set · ❌ Off or no addressAuto
N/A if no data
MAL-53 Outlook add-in installation restricted
L2
Checks whether the default role assignment policy grants users the ability to install Outlook add-ins; unrestricted add-in installation can lead to malicious or data-exfiltrating add-ins.✅ No add-in installation role in the default policy · ❌ At least one add-in installation role assignedAuto
N/A if no data
MAL-54 Defender real-time protection enabled
L1
Checks that Defender Antivirus real-time protection is enabled in the assigned Intune policies. When it is off, malicious files go unnoticed until they run.✅ Real-time protection on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-55 Defender behavior monitoring enabled
L1
Checks that Defender Antivirus behavior monitoring is enabled. Behavior monitoring catches malware with no known signature by how it acts at runtime.✅ Behavior monitoring on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-56 Defender cloud protection enabled
L1
Checks that Defender cloud-delivered protection is enabled. Cloud protection uses Microsoft threat intelligence that updates within minutes of a new threat.✅ Cloud protection on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-57 Defender cloud block level set to High
L2
Checks that the cloud block level is at least High. At a lower level Defender lets through files that are suspicious but not yet confirmed malicious.✅ High or above · ❌ LowerAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-58 Defender script scanning enabled
L1
Checks that script scanning is enabled. Scripts such as PowerShell and JavaScript are the most common first step in modern attacks.✅ Script scanning on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-59 Defender archive scanning enabled
L1
Checks that scanning inside compressed files (ZIP, RAR) is enabled. Malware is routinely hidden inside archives to evade detection.✅ Archive scanning on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-60 Defender email scanning enabled
L1
Checks that endpoint email scanning is enabled. It catches malware in mailbox files and in attachments that reach the local client.✅ Email scanning on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-61 Defender network file scanning enabled
L2
Checks that scanning of files accessed over the network is enabled. When off, malware on a shared folder is not scanned as it is opened.✅ Network file scanning on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-62 Defender removable drive scanning enabled
L1
Checks that removable drives such as USB sticks are included in the full scan.✅ Removable drive scanning on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-63 Defender potentially unwanted app (PUA) protection enabled
L1
Checks that potentially unwanted application protection is enabled. PUAs include adware, browser hijackers and bundled software.✅ PUA protection on (block or audit) · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-64 Defender network protection enabled
L1
Checks that network protection is enabled. It blocks users from connecting to malicious domains and IP addresses.✅ Network protection on (block or audit) · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-65 Defender sample submission enabled
L2
Checks that automatic submission of suspicious file samples to Microsoft is enabled. Sample submission is what lets cloud protection reach a verdict.✅ Sample submission on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-66 Defender signature update interval at most 4 hours
L2
Checks that the signature update interval is set between 1 and 4 hours. If the setting is not defined in the policy, the Windows default applies and we report N/A because we cannot read it.✅ Interval 1-4 hours · ❌ Outside that rangeAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-67 Defender check for signatures before scan enabled
L2
Checks that signatures are updated before a scheduled scan starts. Otherwise the scan runs on stale signatures and a clean result is misleading.✅ Check before scan on · ❌ OffAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-68 Local admin merge of Defender settings disabled
L1
Checks that a local administrator on the device cannot merge their own Defender exclusions into the central policy.✅ Local merge disabled · ❌ EnabledAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise
MAL-69 Defender cloud extended timeout set to 30-50 seconds
L2
Checks that the extended cloud check timeout is set between 30 and 50 seconds. The 10-second default is often not enough for the cloud to reach a verdict.✅ Timeout 30-50 seconds · ❌ Outside that rangeAuto
Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise