Skip to main content
Version: 2.1.1-preview

MT.1151 - Email Scanning should be enabled

Overview

Verify that email scanning is enabled for Exchange queues protection.

Disabled email scanning allows malware to enter through Exchange message queues.

Remediation action:

  1. Open Microsoft Endpoint Manager > Endpoint Security > Antivirus
  2. Edit the relevant Microsoft Defender Antivirus policy
  3. Enable Allow Email Scanning

Test Metadata

FieldValue
Test IDMT.1151
SeverityHigh
SuiteMaester
CategoryDefender
PowerShell testTest-MtMdeEmailScanning
TagsDefender, Maester, MT.1151

Source

  • Pester test: tests/Maester/Defender/Test-MtMdeAntivirusPolicy.Tests.ps1
  • PowerShell source: powershell/public/maester/defender/Test-MtMdeEmailScanning.ps1