2.4 Ensure Office 365 ATP for SharePoint, OneDrive, and Microsoft Teams is Enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Office 365 ATP for SharePoint, OneDrive, and Microsoft Teams scans these services for malicious files.

Rationale:

Office 365 ATP for SharePoint, OneDrive, and Microsoft Teams protects your organization from inadvertently sharing malicious files. When a malicious file is detected, that file is blocked so that no one can open, copy, move, or share it until further actions are taken by the organization's security team.

Impact:

Impact associated with O365 ATP is minimal, and equivalent to impact associated with anti-virus scanners in an environment.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable O365 ATP for SharePoint, OneDrive, and Microsoft Teams, use the Microsoft 365 Admin Center:

Under Admin centers click Security to open the Microsoft 365 Security Center.

Expand Threat management then select Policy, then click Safe Attachments.

Click Global Settings.

Click the toggle so that Turn on Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams is turned on.

To enable O365 ATP for SharePoint, OneDrive, and Microsoft Teams, use the Exchange Online PowerShell Module:

Connect using Connect-EXOPSSession.

Run the following PowerShell command:

Set-AtpPolicyForO365 -EnableATPForSPOTeamsODB $True

See Also

https://workbench.cisecurity.org/files/3433