4.8 Ensure the Advanced Threat Protection Safe Attachments policy is enabled

Information

Enabling the Advanced Threat Protection Safe Attachments policy extends malware protections to include routing all messages and attachments without a known malware signature to a special hypervisor environment. In that environment, a behavior analysis is performed using a variety of machine learning and analysis techniques to detect malicious intent.

Rationale:

This policy increases the likelihood of identifying and stopping previously unknown malware.

Impact:

Delivery of email with attachments may be delayed while scanning is occurring.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable the ATP Safe Attachments policy, use the Microsoft 365 Admin Center:

Click Security to open the Security portal.

Navigate to Threat management, then Policy, select Safe Attachments.

Click +.

Enter Policy Name and Description followed by the Users, Groups, or Domains it will apply to.

Select Block, Monitor, Replace or Dynamic Delivery based on your organizational policies.

Select Next.

Select Submit followed by Done.

Default Value:

disabled

See Also

https://workbench.cisecurity.org/files/3433