CIS Benchmark for M365 and Exchange
This will be my post on LinkedIn and X (Twitter) about CIS policies. We are all trying to secure our environment as much as possible, however, we keep it accessible so users can do their jobs. I came across a recommendation to secure Office and Exchange by using Microsoft Defender for Office, which involves configuring an Antimalware policy to block certain file types. On page 109 of the CIS Benchmark version 5.0 for M365 Level 2 Security, blocking file types is discussed, and a list of files included in that script is provided. Please review and note that I found one of the files is (. ics ), which is used as the main file for webinars and attending online sessions like Microsoft events. These events will be blocked. So if you applied it without reviewing all extensions, you'll encounter the same issue I did, since I applied the policy and don't see a Microsoft event coming when I registered for it. So I reviewed the policy today and found this...