Skip to content

Ensure the connection filter IP allow list is not used (Only Checks Default Policy)

Why This Matters

Maintaining an IP allow list in the connection filter can introduce security blind spots, as it permits all email from specified IP addresses to bypass standard anti-spam and anti-malware scanning. This increases the risk of malicious messages, phishing attempts, or spoofed emails reaching your users. Administrators should review and remove any unnecessary allow list entries to ensure consistent protection for all inbound traffic.

What Aether365 Checks

Aether365 verifies whether the IP allow list in the default connection filter policy is empty or contains entries. This check appears in your Aether365 dashboard under the microsoft-365 category as part of the CIS framework benchmark.

How to Fix

Follow these steps to remove entries from the IP allow list in the default connection filter policy:

Was this page helpful?