O365-OU-000006 - The junk email protection level must be set to No Automatic Filtering.

Information

This policy setting controls the Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk email messages, also known as spam, from cluttering a user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to determine if it is likely spam.

A Junk E-mail filtering option of 'No Automatic Filtering' will evaluate emails against domain names and email addresses in the blocked sender list and send them to the Junk E-mail folder.

A Junk E-mail filtering option of 'High' is not recommended when behind enterprise-level capabilities such as Enterprise Email Security Gateway (EEMSG), Cloud-Based Internet Isolation (CBII), and O365 Exchange Online Protection (EOP).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

In Outlook, click Home tab >> Delete group >> Junk >> Junk E-mail Options.

Set the Junk E-mail protection level to 'No Automatic Filtering'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Office_365_ProPlus_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-223351r961863_rule, STIG-ID|O365-OU-000006, STIG-Legacy|SV-108881, STIG-Legacy|V-99777, Vuln-ID|V-223351

Plugin: Windows

Control ID: 08b393e4f94e700b33107127ef46692ef3f87c20a809b3d4a170ea25efc0c2f8