2.3 Ensure O365 ATP SafeLinks for Office Applications is Enabled

Information

Enabling the Advanced Threat Protection (ATP) Safe Links policy for Office applications allows URL's that existing inside of Office documents opened by Office, Office Online and Office mobile to be processed against ATP time-of-click verification.

Rationale:

ATP Safe Links for Office applications extends phishing protection to documents that contain hyperlinks, even after they have been delivered to a user.

Impact:

User impact associated with this change is minor - users may experience a very short delay when clicking on URLs in Office documents before being directed to the requested site.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable the ATP Safe Links policy for Office, use the Microsoft 365 Admin Center:

Under Admin centers click Security.

Navigate to Threat management and select Policy

Select Safe Links followed by Global Settings.

Select Use Safe Links in Office 365 apps and Do not let users click through to the original URL in Office 365 apps.

Click Save

To enable the ATP Safe Links policy for Office 365, use the Exchange Online PowerShell Module:

Connect using Connect-EXOPSSession.

Run the following PowerShell command:

Set-AtpPolicyForO365 -AllowClickThrough $False -EnableSafeLinksForClients $true

See Also

https://workbench.cisecurity.org/files/3433