2.1.2 (L1) Ensure the Common Attachment Types Filter is enabled

Information

The Common Attachment Types Filter lets a user block known and custom malicious file types from being attached to emails.

Blocking known malicious file types can help prevent malware-infested files from infecting a host.

Solution

To remediate using the UI:

- Navigate to Microsoft 365 Defender

https://security.microsoft.com

.
- Click to expand Email & collaboration select Policies & rules
- On the Policies & rules page select Threat policies
- Under polices select Anti-malware and click on the Default (Default) policy.
- On the Policy page that appears on the right hand pane scroll to the bottom and click on Edit protection settings check the Enable the common attachments filter
- Click Save.

To remediate using PowerShell:

- Connect to Exchange Online using Connect-ExchangeOnline
- Run the following Exchange Online PowerShell command:

Set-MalwareFilterPolicy -Identity Default -EnableFileFilter $true

Note: Audit and Remediation guidance may focus on the Default policy however, if a Custom Policy exists in the organization's tenant, then ensure the setting is set as outlined in the highest priority policy listed.

Impact:

Blocking common malicious file types should not cause an impact in modern computing environments.

See Also

https://workbench.cisecurity.org/benchmarks/17682

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-8, CSCv7|7.9, CSCv7|8.1

Plugin: microsoft_azure

Control ID: 2cf8b37b16c7fd681322be71dd387ab96af06807546eb0f69a38777fedb78592