CTD-000210

Exchange Online organization with no anti-phishing impersonation protection

High
Entra ID Exchange Online
Initial Access

Signature Identity

CTD-000210
Threat ID
Version
IOE
Indicator Type

Threat Description

An Exchange Online organization that has no user and domain impersonation protection in its anti-phishing policy is vulnerable, because the tenant accepts messages that mimic the display name or domain of executives, partners, or the organization itself. A threat actor exploits this gap by registering a lookalike domain or spoofing a trusted display name to solicit fraudulent payments or credentials, activity that impersonation protection is designed to detect and flag. Impersonation protection closes the gap because it compares each sender against the identities and domains you protect, and then acts when it finds a mismatch.

Example: A threat actor registers contos0.com and emails the accounts payable team using the CEO’s display name to request an urgent invoice payment. Without impersonation protection for the CEO’s identity, the message is delivered normally. With protection enabled, the mismatch between the sender’s actual domain and the protected identity triggers a warning or quarantines the message.

MITRE ATT&CK: Attack Tactics

Initial Access

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Sign in to the Microsoft Defender portal.
  2. Under Email & collaboration, select Policies & rules.
  3. Select Threat policies.
  4. Under Policies, select Anti-phishing.
  5. Select the Office365 AntiPhish Default (Default) policy.
  6. Select Edit protection settings.
  7. Under Impersonation, select Enable users to protect.
  8. Select Manage (nn) sender(s).
  9. On the Manage senders for impersonation protection page, select Add user.
  10. Enter a name and a valid email address for each high-value identity, and then select Add after each one.
  11. Select Done.
  12. Select Enable domains to protect.
  13. Select the Include domains I own checkbox.
  14. Optional: To protect partner domains, do the following:
    1. Select the Include custom domains checkbox.
    2. Select Manage (nn) custom domain(s).
    3. Add each partner domain, and then select Done.
  15. Select Save.
  16. Select Edit actions.
  17. Under If a message is detected as user impersonation, select one of the following actions:
    • Redirect the message to other email addresses.
    • Move the message to the recipients’ Junk Email folders.
    • Quarantine the message.
    • Deliver the message and add other addresses to the Bcc line.
    • Delete the message before it’s delivered.
  18. Under If a message is detected as domain impersonation, select one of the following actions:
    • Redirect the message to other email addresses.
    • Move the message to the recipients’ Junk Email folders.
    • Quarantine the message.
    • Deliver the message and add other addresses to the Bcc line.
    • Delete the message before it’s delivered.
  19. Select Save.

Frequently Asked Questions

What does Exchange Online organization with no anti-phishing impersonation protection mean?

An Exchange Online organization that lacks user and domain impersonation protection in its anti-phishing policy is susceptible to attacks that exploit lookalike domains and spoofed display names, allowing attackers to send emails that appear to originate from trusted sources.

This vulnerability enables attackers to register lookalike domains or spoof trusted display names, tricking recipients into divulging sensitive information or credentials. This can lead to unauthorized access and data breaches.

Attackers can register a lookalike domain or spoof a trusted display name to send emails that appear to originate from a trusted source, tricking recipients into divulging sensitive information or credentials. This can support later attacker activity, such as phishing or business email compromise attacks.

Cayosoft Guardian continuously monitors for Exchange Online organization with no anti-phishing impersonation protection and alerts administrators when the condition is detected. This provides visibility into the exposure so security teams can review the finding and determine whether investigation or response is required. Guardian monitors Exchange Online and Entra ID for this condition and flags it when detected.

Cayosoft Guardian helps reduce the risk of Exchange Online organization with no anti-phishing impersonation protection by alerting administrators when the condition is detected and providing visibility into the affected mailboxes, inbox rules, and permissions. This helps security teams identify exposure more quickly and respond before the issue contributes to a larger security event.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Mailbox protection
Attack Tactics
Initial Access
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical