5.14 Ensure the report of users who have had their email privileges restricted due to spamming is reviewed

Information

Review and unblock users who have been blocked for sending too many messages marked as spam/bulk.

Rationale:

Users who are found on the restricted users list have a high probability of having been compromised. Review of this list will allow an organization to remediate these user accounts, and then unblock them.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the report, use the Microsoft 365 Admin Center:

Select Security.

Select Threat Management and Review.

Click Restricted Users (or navigate directly to https://protection.office.com/restrictedusers).

Review alerts and take appropriate action (unblocking) after account has been remediated.

See Also

https://workbench.cisecurity.org/files/3433