MAL — Email & Threat Protection
Email authentication and malware protections. 64 controls in total — 63 automatic, 1 attested.
How to read
Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.
| Control | What it checks | Result criteria | Status |
|---|---|---|---|
MAL-01 SPF record (all domains) L1 | Checks whether your email is protected against spoofed sending in your name, across all domains. | ✅ Valid on all domains · ❌ Any missing | Auto N/A if no data |
MAL-02 DMARC record (all domains) L1 | Checks whether spoofed email is blocked by completing SPF/DKIM validation, across all domains. | ✅ Valid on all domains · ❌ Any missing | Auto N/A if no data |
MAL-03 Automatic email forwarding block L1 | Checks whether incoming email is auto-forwarded outside the organization. It prevents data leakage. | ✅ Forwarding off · ⚠️ On up to 5 mailboxes, no rule, auto-forward off · ❌ More than that | Auto N/A if no data |
MAL-04 Legacy SMTP authentication disabled L1 | Checks the open door that legacy email protocols leave to brute-force and spam attacks. | ✅ Off for everyone · ⚠️ On for up to 5 users · ❌ On for more than 5 users | Auto N/A if no data |
MAL-07 Meeting lobby (organization only) L1 | Checks whether outside people can join meetings directly without passing through the lobby. | ✅ Organization only can join · ❌ Outsiders can join too | Auto N/A if no data |
MAL-09 Outbound email spam filter L1 | Checks the filter that stops a compromised account from sending spam outside. | ✅ Configured · ❌ Not configured | Auto N/A if no data |
MAL-10 Safe Attachments policy L1 | Checks whether malicious email attachments are scanned and blocked. | ✅ Enabled · ❌ Disabled | Auto Requires Microsoft 365 E3; N/A without Global Reader or data |
MAL-11 Safe Links policy L1 | Checks whether clicks on malicious links in email are blocked. | ✅ Enabled · ❌ Disabled | Auto Requires Microsoft 365 E3; N/A without Global Reader or data |
MAL-12 DKIM signing (all domains) L1 | Checks the digital signature against email forgery across all domains. | ✅ Configured on all domains · ❌ Any missing | Auto N/A if no data |
MAL-13 Impersonation protection L1 | Checks the protection against phishing attacks that impersonate senior executives. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-15 Modern authentication (Exchange) L1 | Checks the modern authentication that stops legacy auth from bypassing multi-step verification. | ✅ Enabled · ❌ Disabled | Auto N/A if no data |
MAL-16 Mailbox audit logging L1 | Checks whether mailbox access is logged. It makes breach detection possible. | ✅ On · ❌ Off | Auto N/A if no data |
MAL-17 Dangerous file extension filter L1 | Blocks harmful file extensions from arriving by email and being run by mistake. It lowers ransomware risk. | ✅ Enabled · ❌ Disabled | Auto N/A if no data |
MAL-18 Safe Attachments (unknown threat analysis) L2 | Checks whether unknown malware is analyzed in an isolated environment. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P1; N/A without Global Reader or data |
MAL-19 Safe Attachments (SharePoint/OneDrive/Teams) L2 | Checks whether malicious files shared in SharePoint, OneDrive and Teams are scanned. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P1; N/A without Global Reader or data |
MAL-20 Outbound spam admin notification L1 | Checks whether the admin is alerted if a compromised account starts sending spam outside. | ✅ Notification on · ❌ Off | Auto N/A if no data |
MAL-21 Extended file extension filter L2 | Checks whether rare dangerous extensions beyond the default list are also blocked. | ✅ Extended list applied · ❌ Default only / incomplete | Auto N/A if no data |
MAL-22 No IP allow list in the connection filter L1 | Stops IPs on an allow list from bypassing spam and phishing checks. | ✅ Allow list empty · ❌ IP allow list defined | Auto N/A if no data |
MAL-23 Connection filter safe list disabled L1 | Stops an unmanaged whitelist from bypassing the security scan. | ✅ Off · ❌ On | Auto N/A if no data |
MAL-24 No allowed sender domain list on inbound email L1 | Stops allowed sender domains from bypassing spam and phishing checks. | ✅ No allowed domain · ❌ Allowed domain defined | Auto N/A if no data |
MAL-25 Outbound email message limits L1 | Checks the limits that cap bulk spam sending from a compromised account. | ✅ Limits configured · ❌ Not configured | Auto N/A if no data |
MAL-26 Break-glass account monitoring L1 | Checks whether use of emergency admin accounts is monitored. | Attested Customer attestation (not measured automatically) | |
MAL-27 Priority account protection L1 | Checks the protection against targeted phishing (whaling) aimed at senior executives. | ✅ Priority account protection on · ❌ Off | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-28 Strict protection profile for priority accounts L1 | Checks whether Microsoft's strictest security profile is applied to priority accounts. | ✅ Strict protection applied · ❌ Not applied | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-30 Automatic threat purge for Teams (ZAP) L1 | Checks whether links later found malicious in Teams messages are removed automatically. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-31 Mailbox audit bypass disabled L1 | Checks that no mailbox bypasses the audit log. | ✅ No mailbox bypasses auditing · ❌ A mailbox has bypass on | Auto N/A if no data |
MAL-32 Transport rules add no domain whitelist L1 | Checks that transport rules do not bypass the spam filter for specific domains. | ✅ No filter-bypassing rule · ❌ A filter-bypassing rule exists | Auto N/A if no data |
MAL-33 External sender tagging L1 | Checks whether email from outside is visually tagged. It makes spoofed email easier to spot. | ✅ Tagging on · ❌ Off | Auto N/A if no data |
MAL-34 MailTips warnings (end users) L1 | Checks whether critical warnings, such as an external recipient or a large distribution group, are shown to the user. | ✅ On · ❌ Off | Auto N/A if no data |
MAL-35 Restricting extra cloud storage in Outlook on the web L2 | Checks whether third-party cloud storage links (Dropbox, Google Drive and the like) are restricted in Outlook on the web. | ✅ Restricted · ❌ Left open | Auto N/A if no data |
MAL-36 Direct Send submissions rejected L2 | Stops mail sent by connecting directly from outside and appearing to come from inside. | ✅ Rejected · ❌ Allowed | Auto N/A if no data |
MAL-37 Anonymous meeting join disabled L2 | Checks whether unverified anonymous users are blocked from joining Teams meetings; anonymous access can let unauthorized people into a meeting. | ✅ Anonymous join off · ❌ On | Auto N/A if no data |
MAL-38 Anonymous/dial-in meeting start disabled L1 | Checks whether anonymous or dial-in users are blocked from starting a meeting with no host present; an early start weakens meeting control. | ✅ Anonymous/dial-in start off · ❌ On | Auto N/A if no data |
MAL-39 Dial-in users cannot bypass the lobby L1 | Checks whether dial-in (PSTN) callers are prevented from joining a meeting directly without passing through the lobby. | ✅ Dial-in cannot bypass lobby · ❌ Can bypass | Auto N/A if no data |
MAL-40 Anonymous users blocked from meeting chat L2 | Checks whether anonymous users are blocked from reading and writing in the meeting chat; anonymous chat access carries abuse and link-sharing risk. | ✅ Meeting chat excludes anonymous or is off · ❌ Anonymous can chat too | Auto N/A if no data |
MAL-41 Only organizers/co-organizers can present L2 | Checks whether only organizers and co-organizers can present in a meeting; letting everyone present opens the door to screen and content abuse. | ✅ Only organizers/co-organizers can present · ❌ Everyone can present | Auto N/A if no data |
MAL-42 External participants cannot request/give control L1 | Checks whether external participants are blocked from requesting or being given presentation control; handing over control grants an outsider authority over the screen. | ✅ External participants cannot give/request control · ❌ Can request and receive it | Auto N/A if no data |
MAL-43 External (untrusted) meeting chat disabled L2 | Checks whether meeting chat with untrusted external organizations is turned off; untrusted external chat is a vector for malicious links and file delivery. | ✅ Untrusted external meeting chat off · ❌ On | Auto N/A if no data |
MAL-44 Meeting recording off by default L2 | Checks whether cloud recording is off by default in the global meeting policy; letting anyone record can lead to sensitive conversations being stored without consent. | ✅ Meeting recording off · ❌ On | Auto N/A if no data |
MAL-45 Third-party file storage disabled L2 | Checks whether third-party storage providers such as Dropbox, Box, Google Drive, ShareFile and Egnyte are turned off in Teams; unapproved cloud storage carries data-leakage risk. | ✅ No third-party storage provider enabled · ❌ At least one enabled | Auto N/A if no data |
MAL-46 Email into channel disabled L2 | Checks whether sending email directly into a Teams channel is turned off; email-into-channel lets unfiltered external content land in a channel. | ✅ Email into channel off · ❌ On | Auto N/A if no data |
MAL-47 Consumer Teams federation disabled L1 | Checks whether communication with personal (consumer) Teams accounts is turned off; contact with unmanaged personal accounts is a vector for data leakage and social engineering. | ✅ Personal Teams federation off · ❌ On | Auto N/A if no data |
MAL-48 Inbound consumer Teams invites disabled L1 | Checks whether personal Teams accounts are blocked from initiating first contact with the organization; inbound personal invites open first contact from unmanaged accounts. | ✅ Inbound personal Teams invites off · ❌ On | Auto N/A if no data |
MAL-49 Trial tenant external access blocked L2 | Checks whether external access with unverified trial tenants is blocked; trial tenants are short-lived and prone to abuse. | ✅ Trial tenant external access blocked · ❌ Allowed | Auto N/A if no data |
MAL-50 Federation limited to authorized domains L1 | Checks whether Teams federation is off or limited to an allow-list of authorized domains; federation open to all external domains is a broad attack surface. | ✅ Federation off or limited to authorized domains · ❌ Open to all known domains | Auto N/A if no data |
MAL-51 User security reports stay in-house L1 | Checks whether users can report suspicious messages in Teams and whether those reports go to the organization's own mailbox rather than to Microsoft; reports that do not stay in-house reduce the internal security team's visibility. | ✅ Teams end-user reporting on and reports routed to the organization mailbox · ❌ Reporting off or reports not routed in-house | Auto Requires E5; N/A without Global Reader or data |
MAL-52 Admin notification on internal malware sending L1 | Checks whether an admin is notified when an internal user sends malware (in the default anti-malware policy); without notification, an internally sourced infection is noticed late. | ✅ Internal sender admin notification on with an address set · ❌ Off or no address | Auto N/A if no data |
MAL-53 Outlook add-in installation restricted L2 | Checks whether the default role assignment policy grants users the ability to install Outlook add-ins; unrestricted add-in installation can lead to malicious or data-exfiltrating add-ins. | ✅ No add-in installation role in the default policy · ❌ At least one add-in installation role assigned | Auto N/A if no data |
MAL-54 Defender real-time protection enabled L1 | Checks that Defender Antivirus real-time protection is enabled in the assigned Intune policies. When it is off, malicious files go unnoticed until they run. | ✅ Real-time protection on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-55 Defender behavior monitoring enabled L1 | Checks that Defender Antivirus behavior monitoring is enabled. Behavior monitoring catches malware with no known signature by how it acts at runtime. | ✅ Behavior monitoring on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-56 Defender cloud protection enabled L1 | Checks that Defender cloud-delivered protection is enabled. Cloud protection uses Microsoft threat intelligence that updates within minutes of a new threat. | ✅ Cloud protection on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-57 Defender cloud block level set to High L2 | Checks that the cloud block level is at least High. At a lower level Defender lets through files that are suspicious but not yet confirmed malicious. | ✅ High or above · ❌ Lower | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-58 Defender script scanning enabled L1 | Checks that script scanning is enabled. Scripts such as PowerShell and JavaScript are the most common first step in modern attacks. | ✅ Script scanning on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-59 Defender archive scanning enabled L1 | Checks that scanning inside compressed files (ZIP, RAR) is enabled. Malware is routinely hidden inside archives to evade detection. | ✅ Archive scanning on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-60 Defender email scanning enabled L1 | Checks that endpoint email scanning is enabled. It catches malware in mailbox files and in attachments that reach the local client. | ✅ Email scanning on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-61 Defender network file scanning enabled L2 | Checks that scanning of files accessed over the network is enabled. When off, malware on a shared folder is not scanned as it is opened. | ✅ Network file scanning on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-62 Defender removable drive scanning enabled L1 | Checks that removable drives such as USB sticks are included in the full scan. | ✅ Removable drive scanning on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-63 Defender potentially unwanted app (PUA) protection enabled L1 | Checks that potentially unwanted application protection is enabled. PUAs include adware, browser hijackers and bundled software. | ✅ PUA protection on (block or audit) · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-64 Defender network protection enabled L1 | Checks that network protection is enabled. It blocks users from connecting to malicious domains and IP addresses. | ✅ Network protection on (block or audit) · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-65 Defender sample submission enabled L2 | Checks that automatic submission of suspicious file samples to Microsoft is enabled. Sample submission is what lets cloud protection reach a verdict. | ✅ Sample submission on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-66 Defender signature update interval at most 4 hours L2 | Checks that the signature update interval is set between 1 and 4 hours. If the setting is not defined in the policy, the Windows default applies and we report N/A because we cannot read it. | ✅ Interval 1-4 hours · ❌ Outside that range | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-67 Defender check for signatures before scan enabled L2 | Checks that signatures are updated before a scheduled scan starts. Otherwise the scan runs on stale signatures and a clean result is misleading. | ✅ Check before scan on · ❌ Off | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-68 Local admin merge of Defender settings disabled L1 | Checks that a local administrator on the device cannot merge their own Defender exclusions into the central policy. | ✅ Local merge disabled · ❌ Enabled | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |
MAL-69 Defender cloud extended timeout set to 30-50 seconds L2 | Checks that the extended cloud check timeout is set between 30 and 50 seconds. The 10-second default is often not enough for the cloud to reach a verdict. | ✅ Timeout 30-50 seconds · ❌ Outside that range | Auto Requires an assigned Intune Defender Antivirus policy with this setting defined; N/A otherwise |