Watchtower Docs
ReferenceCheck catalog

Microsoft 365 platform

All 7 Microsoft 365 platform checks - what each one checks, why, and the access used to evaluate it.

7 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.

CheckSeverityWhat it checksWhy it mattersAccess used
Customer lockbox feature is enabled
wt.m365.customer-lockbox-enabled
MEDIUMChecks that the Customer Lockbox feature is enabled, requiring explicit customer approval before Microsoft support engineers can access tenant content during a support request.Without Customer Lockbox, Microsoft engineers can access tenant content (mailboxes, files, etc.) to resolve support tickets without customer knowledge. Enabling it ensures that any such access requires explicit approval from a designated administrator, providing an audit trail and protecting against insider threats at the Microsoft support level.Exchange.ManageAsApp - via organizationConfig
Internal phishing protection for Forms is enabled
wt.m365.forms-phishing-protection
MEDIUMChecks that Microsoft Forms is configured to scan forms created by users in the organisation for phishing content and block submission when suspicious content is detected.Microsoft Forms can be weaponised by attackers who have compromised a tenant user account to create convincing credential-harvesting forms that appear to come from the organisation. Internal phishing scanning detects and blocks forms that attempt to collect sensitive information under false pretences, limiting insider-facilitated phishing attacks.OrgSettings-Forms.Read.All - via formsSettings
Idle session timeout is set to 3 hours or less (policy)
wt.m365.idle-session-timeout-policy
MEDIUMChecks that the Microsoft 365 idle session timeout policy is configured to sign out browser sessions after 3 hours of inactivity or less.Browser sessions left open on unattended workstations, shared terminals, or personal devices expose authenticated access to anyone with physical access to the machine. An idle session timeout ensures that inactivity closes the session, requiring reauthentication before corporate data can be accessed.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Users cannot access the Office Store
wt.m365.office-store-disabled
MEDIUMChecks that access to the Office Add-ins Store is disabled for users, preventing self-service installation of Office add-ins from the public marketplace.The public Office Store contains add-ins from unvetted third-party developers that can access mailbox content, documents, and other data in the context of the user's session. Malicious or compromised add-ins represent a supply-chain attack vector for credential theft and data exfiltration.OrgSettings-AppsAndServices.Read.All - via appsAndServices
Users cannot start trials on behalf of the organization
wt.m365.org-trials-disabled
MEDIUMChecks that users are prevented from initiating Microsoft 365 service trials on behalf of the organisation, ensuring new services are evaluated and approved through a controlled process.Self-service trials introduce new services - and their associated data-sharing and permission models - into the tenant without IT or security review. Attackers who compromise a user account can also use trial activations to probe available services or gain access to capabilities that should be restricted.OrgSettings-AppsAndServices.Read.All - via appsAndServices
Sways cannot be shared with people outside of the organization
wt.m365.sway-external-sharing-disabled
MEDIUMChecks that Microsoft Sway is configured to prevent users from sharing presentations and reports externally, limiting Sway content to internal audiences only.Sway documents can contain sensitive organisational content - strategies, financial data, personnel information - that users may inadvertently share publicly via anonymous links. External sharing with no access control allows anyone with the link to access the content permanently, creating a persistent data leakage risk.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Third-party storage services are restricted in Microsoft 365 on the web
wt.m365.third-party-storage-disabled
MEDIUMChecks that users are prevented from connecting third-party cloud storage services (such as Dropbox, Box, or Google Drive) to Microsoft 365 web applications.Third-party cloud storage integrations bypass corporate DLP controls and data governance policies, allowing users to move sensitive data to unmanaged external services. This creates an uncontrolled data exfiltration path that is difficult to detect and audit.Exchange.ManageAsApp - via owaMailboxPolicies