STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Edge Server Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 30 Jan 2025:

Exchange messages with a blank sender field must be filtered.

DISA Rule

SV-259610r961161_rule

Vulnerability Number

V-259610

Group Title

SRG-APP-000261

Rule Version

EX19-ED-000124

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the Exchange Management Shell and enter the following command:

Set-SenderFilterConfig -BlankSenderBlockingEnabled $true

Check Contents

This requirement is Not Applicable for SIPR enclaves.

This requirement is Not Applicable if the organization subscribes to EEMSG or other similar DOD enterprise protections for email services.

Open the Exchange Management Shell and enter the following command:

Get-SenderFilterConfig | Select-Object -Property Name, BlankSenderBlockingEnabled

If the value of "BlankSenderBlockingEnabled" is not set to "True", this is a finding.

Vulnerability Number

V-259610

Documentable

False

Rule Version

EX19-ED-000124

Severity Override Guidance

This requirement is Not Applicable for SIPR enclaves.

This requirement is Not Applicable if the organization subscribes to EEMSG or other similar DOD enterprise protections for email services.

Open the Exchange Management Shell and enter the following command:

Get-SenderFilterConfig | Select-Object -Property Name, BlankSenderBlockingEnabled

If the value of "BlankSenderBlockingEnabled" is not set to "True", this is a finding.

Check Content Reference

M

Target Key

5579