5.14 Ensure the report of users who have had their email privileges restricted due to spamming is reviewed

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Review and unblock users who have been blocked for sending too many messages marked as spam/bulk.

Rationale:

Users who are found on the restricted users list have a high probability of having been compromised. Review of this list will allow an organization to remediate these user accounts, and then unblock them.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the report, use the Microsoft 365 Admin Center:

Click Security to open the Security portal.

Under Email & collaboration navigate to Review.

Click Restricted Users.

Review alerts and take appropriate action (unblocking) after account has been remediated.

See Also

https://workbench.cisecurity.org/files/3729