cisagov / ScubaGear

Automation to assess the state of your M365 tenant against CISA's baselines
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
1.76k stars 226 forks source link

Conduct hands-on examination of organization and user level audit settings for Exchange Online mailboxes #1433

Open tkol2022 opened 3 days ago

tkol2022 commented 3 days ago

💡 Summary

Perform hands-on tests of Exchange Online mailbox audit settings to understand how each configuration behaves in practice and the relationships between settings. There are numerous mailbox audit settings at both the organizational level and the user level and it is unclear how they behave in practice. The output of this investigation will produce test results that will inform new secure configuration policies for Exchange Online #1072.

The scope of this testing covers the following settings:

Motivation and context

Without a hands-on test of all permutations of audit settings we won't know what the risks are and how to mitigate them with SCB policies.

Implementation notes