ReferenceCheck catalog
Microsoft Defender
All 14 Microsoft Defender checks - what each one checks, why, and the access used to evaluate it.
14 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.
| Check | Severity | What it checks | Why it matters | Access used |
|---|---|---|---|---|
An anti-phishing policy has been createdwt.defender.anti-phishing-policy-exists | HIGH | Verifies that an anti-phishing policy exists and is configured with impersonation protection, spoof intelligence, mailbox intelligence, and aggressive quarantine actions for both targeted users and domains. | Phishing is the leading initial-access vector in corporate breaches. Without a hardened anti-phishing policy, attackers can impersonate executives or trusted domains to harvest credentials or deliver malware, enabling account takeover and lateral movement across the tenant. | Exchange.ManageAsApp - via antiPhishPolicies |
Inbound anti-spam policies do not contain allowed domainswt.defender.anti-spam-no-allowed-domains | MEDIUM | Checks that no inbound anti-spam policy contains entries in the allowed-sender-domains list, which would bypass spam filtering for all mail from those domains. | Domain-level allow-list entries are frequently abused in business email compromise attacks: once a spoofed or compromised domain is on the list, malicious messages skip spam scoring entirely, enabling credential phishing and malware delivery that would otherwise be blocked. | Exchange.ManageAsApp - via hostedContentFilterPolicies |
Microsoft Defender for Cloud Apps is enabled and configuredwt.defender.cloud-app-security-enabled | HIGH | Verifies that Microsoft Defender for Cloud Apps is enabled for the tenant and that app governance and relevant cloud-app policies - including anomaly detection, access policies, and session policies - are actively configured. | Without Cloud App Security, shadow IT usage, risky OAuth app consents, and anomalous user behaviour in SaaS applications go undetected. Attackers exploit unmonitored OAuth grants and abnormal session activity for data exfiltration and persistent access after credential compromise. | None - no tenant data read (not automatable via API, reported as a manual/indeterminate result) |
Common Attachment Types Filter is enabledwt.defender.common-attachment-filter-enabled | MEDIUM | Checks that the Common Attachment Types Filter is enabled in every malware filter policy, causing Exchange Online to block delivery of file types commonly associated with malware. | Executable and script file types - such as .exe, .js, .vbs, and .ps1 - are the primary carriers for ransomware and remote-access trojans delivered via email. Blocking these file types at the gateway prevents malware delivery even when sandboxing is unavailable or bypassed. | Exchange.ManageAsApp - via malwareFilterPolicies |
Comprehensive attachment filtering is appliedwt.defender.comprehensive-attachment-filtering | HIGH | Verifies that the Common Attachment Types Filter is enabled across all malware filter policies - including the Default policy - so that every recipient in the tenant is protected from high-risk file-type attachments. | Gaps in attachment filtering coverage allow ransomware and trojan droppers to reach mailboxes not covered by a custom policy. The Default malware filter policy applies to all users not explicitly covered by a higher-priority custom policy, so leaving it without file filtering creates a blind spot for malware delivery. | Exchange.ManageAsApp - via malwareFilterPolicies |
Connection filter IP allow list is not usedwt.defender.connection-filter-ip-allowlist-empty | MEDIUM | Checks that the connection filter IP allow list in the Default policy contains no entries, ensuring no IP addresses are permanently exempted from spam and malware filtering. | IP addresses on the connection filter allow list bypass all Exchange Online Protection spam and malware scanning. If a permitted IP is ever compromised or spoofed, attackers can deliver phishing messages and malware-laden attachments directly to user inboxes without any filtering. | Exchange.ManageAsApp - via hostedConnectionFilterPolicies |
Connection filter safe list is offwt.defender.connection-filter-safelist-disabled | MEDIUM | Checks that the Microsoft-maintained safe list (a dynamic list of trusted sending IPs) is disabled in the connection filter policy, preventing its use as an automatic spam bypass. | The connection filter safe list exempts a broad set of Microsoft-maintained IP ranges from spam filtering. Because entries are added automatically and may include shared infrastructure, a compromised or misconfigured IP on the list could be used to bypass filtering and deliver phishing or malware payloads. | Exchange.ManageAsApp - via hostedConnectionFilterPolicies |
Notifications for internal users sending malware is enabledwt.defender.malware-admin-notification-enabled | MEDIUM | Verifies that anti-malware policies are configured to alert a designated administrator whenever an internal user's mailbox is used to send a message containing malware. | Outbound malware from an internal account is a strong indicator of account compromise or an infected endpoint. Early notification allows security teams to contain the compromised account before it is used for further lateral movement, data exfiltration, or internal spear-phishing. | Exchange.ManageAsApp - via malwareFilterPolicies |
Priority account protection is enabled and configuredwt.defender.priority-account-protection-enabled | HIGH | Checks that the Priority account protection feature is enabled in Defender, ensuring elevated threat monitoring for high-value targets such as executives, IT administrators, and finance personnel. | Executives, IT administrators, and finance personnel are disproportionately targeted by spear-phishing and business email compromise. Priority account protection applies stricter heuristics and additional threat-intelligence signals to these accounts, reducing the chance of a successful takeover that could lead to wire fraud or tenant-wide compromise. | Exchange.ManageAsApp - via emailTenantSettings |
Priority accounts have Strict protection presets appliedwt.defender.priority-account-strict-preset | HIGH | Verifies that the Strict preset security policy is enabled and assigned to at least one group, ensuring priority accounts receive Microsoft's most aggressive email protection settings. | Priority accounts - executives, admins, finance staff - are the highest-value targets for spear-phishing and business email compromise. The Strict preset applies the most conservative thresholds for anti-spam, anti-phishing, Safe Links, and Safe Attachments, significantly reducing the attack surface for these accounts. | Exchange.ManageAsApp - via eopProtectionPolicyRules |
Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is enabledwt.defender.safe-attachments-cloud-enabled | HIGH | Checks that Safe Attachments scanning is enabled for files stored in SharePoint, OneDrive, and Teams, and that Safe Documents is enforced so users cannot bypass sandbox results to open suspicious files. | Files shared via SharePoint, OneDrive, and Teams are a common vector for ransomware and malware distribution within an organisation. Without cloud-storage Safe Attachments, a malicious file uploaded by an external collaborator or a compromised account can be accessed and executed by any recipient before it is identified as malicious. | Exchange.ManageAsApp - via atpPolicyForO365 |
Safe Attachments policy is enabledwt.defender.safe-attachments-enabled | HIGH | Verifies that a Safe Attachments policy is enabled with Block action and admin-only quarantine access, ensuring email attachments are detonated in a sandbox before delivery. | Safe Attachments is the primary defence against zero-day malware and ransomware delivered via email attachments that signature-based scanning misses. Without it, malicious files reach user mailboxes before detonation analysis completes, enabling drive-by malware execution and ransomware deployment. | Exchange.ManageAsApp - via safeAttachmentPolicies |
Safe Links for Office Applications is enabledwt.defender.safe-links-enabled | HIGH | Verifies that at least one custom Safe Links policy is configured to rewrite and scan URLs in email, Teams, and Office applications, and that users cannot click through to malicious URLs. The Microsoft-managed Built-In Protection Policy is excluded because it uses permissive defaults that do not satisfy CIS requirements. | Credential phishing via malicious URLs is the most common vector for initial access. Safe Links rewrites URLs and performs time-of-click reputation checks, blocking access to phishing pages even when the URL appeared clean at delivery - a technique known as time-of-delivery detonation bypass. Without this control, a URL that was benign at the time of sending can later be weaponised after the email has been delivered. | Exchange.ManageAsApp - via safeLinksPolicies |
Zero-hour auto purge for Microsoft Teams is onwt.defender.teams-zap-enabled | MEDIUM | Checks that Zero-hour Auto Purge (ZAP) is enabled for Microsoft Teams, allowing Defender to retroactively remove malicious messages from Teams chats after delivery when new threat intelligence identifies them as harmful. | Threat intelligence about malicious URLs or files often becomes available after a message has already been delivered. Without Teams ZAP, malicious content shared in chats remains accessible to users indefinitely, enabling malware execution or credential theft long after the initial delivery. | Exchange.ManageAsApp - via teamsProtectionPolicies |