By default, SharePoint Online allows files that Defender for Office 365 has detected as infected to be downloaded. Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams protects your organization from inadvertently sharing malicious files. When an infected file is detected, that file is blocked so that no one can open, copy, move, or share it until the organization’s security team takes further action. This control is part of the CIS Level 2 Security profile, which is considered to be a “defence in depth” where security is parament. Implementing this control can potentially inconvenience users when a small percentage of false positive detection occurs. By default, users can download infected files from SharePoint Online. Here’s what happens: After this security control is applied, users can’t download infected files, even from the anti-virus warning window. It is included at no charge in M365 Security and Compliance Plan 1 and 2 customers. Because this is a Level 2 security control, we require your approval to enable it. In our testing, we have had very few false positives. We recommend that all customers enable this security control. Please send a support request to support@globalmicro.co.za. For more information about our products and services, send us your details and one of our agents will reach out to you.Ensure Office 365 SharePoint infected files are disallowed for download.
Background
What is the rationale for implementing CIS Control 7.3.1 (L2) of the Microsoft 365 Foundations Benchmark?
What is the impact of deploying this security control?
What happens when a user tries to download an infected file by using the browser?
Is there a cost to enabling this capability?
What do I need to do to implement this security control?
Contact Us