Skip to main content

SecureScore for EXO & MDO

Detail: SecureSore List (2025)

TitleServiceMaxScore
Set the phishing email level threshold at 2 or higherMDO8
Move messages that are detected as impersonated users by mailbox intelligenceMDO8
Ensure that intelligence for impersonation protection is enabledMDO8
Ensure that mailbox intelligence is enabledMDO8
Enable impersonated domain protectionMDO8
Turn on Safe Attachments in block modeMDO8
Ensure the Common Attachment Types Filter is enabledMDO5
Ensure Safe Attachments policy is enabledMDO5
Set action to take on phishing detectionMDO5
Set action to take on high confidence spam detectionMDO5
Set action to take on high confidence phishing detectionMDO5
Ensure all forms of mail forwarding are blocked and/or disabledMDO5
Turn on Safe Documents for Office ClientsMDO5
Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft TeamsMDO5
Ensure 'External sharing' of calendars is not availableEXO5
Ensure that SPF records are published for all Exchange DomainsEXO5
Ensure additional storage providers are restricted in Outlook on the webEXO5
Ensure mailbox auditing for all users is EnabledEXO3
Ensure MailTips are enabled for end usersEXO3
Ensure modern authentication for Exchange Online is enabledEXO3
Ensure users installing Outlook add-ins is not allowedEXO3
Ensure that an anti-phishing policy has been createdMDO3
Set action to take on bulk spam detectionMDO3
Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domainsEXO3
Ensure that no sender domains are allowed for anti-spam policiesMDO2
Set automatic email forwarding rules to be system controlledMDO1
Don't add allowed IP addresses in the connection filter policy MDO1
Set the email bulk complaint level (BCL) threshold to be 6 or lowerMDO1
Retain spam in quarantine for 30 daysMDO1
Set maximum number of external recipients that a user can email per hourMDO1
Set maximum number of internal recipients that a user can send to within an hourMDO1
Set a daily message limitMDO1
Ensure the customer lockbox feature is enabledEXO1