Stop Spoofing Yourself! Disabling M365 Direct Send
ID: 4fc06ff7-5cee-555a-ae71-fd03a7b1138b
STIX ID: report--4fc06ff7-5cee-555a-ae71-fd03a7b1138b
Feed Name: Black Hills Infosec Blog
Threat Score
This report explains that Microsoft 365's Direct Send is an unauthenticated SMTP path allowing attackers to send email appearing to originate from internal addresses within a tenant, outlines recent surge in abuse for internal impersonation/phishing, discusses testing caveats, and shows how to enable the public-preview 'Reject Direct Send' setting (Set-OrganizationConfig -RejectDirectSend $true) to block such misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
