2.4.4 (L1) Ensure Zero-hour auto purge for Microsoft Teams is on

Information

Zero-hour auto purge (ZAP) is a protection feature that retroactively detects and neutralizes malware and high confidence phishing. When ZAP for Teams protection blocks a message, the message is blocked for everyone in the chat. The initial block happens right after delivery, but ZAP occurs up to 48 hours after delivery.

ZAP is intended to protect users that have received zero-day malware messages or content that is weaponized after being delivered to users. It does this by continually monitoring spam and malware signatures taking automated retroactive action on messages that have already been delivered.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Defender

https://security.microsoft.com/

- Click to expand System select Settings > Email & collaboration > Microsoft Teams protection
- Set Zero-hour auto purge (ZAP) to On (Default)

To remediate using PowerShell:

- Connect to Exchange Online using Connect-ExchangeOnline
- Run the following cmdlet:

Set-TeamsProtectionPolicy -Identity "Teams Protection Policy" -ZapEnabled $true

Impact:

As with any anti-malware or anti-phishing product, false positives may occur.

See Also

https://workbench.cisecurity.org/benchmarks/17682

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3

Plugin: microsoft_azure

Control ID: 773856c26fff97c6492f3c4624eb4f2ab6eca9195f825a7979af0cdcce6f3baa