STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Edge Server Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 30 Jan 2025:

Role-Based Access Control must be defined for privileged and nonprivileged users.

DISA Rule

SV-259631r961353_rule

Vulnerability Number

V-259631

Group Title

SRG-APP-000340

Rule Version

EX19-ED-000174

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Update the EDSP and define who should and should not have elevated privileges within the organization.

Follow the rule of least privilege and ensure that administrators are given just enough access to complete their job.

Reference document: https://docs.microsoft.com/en-us/exchange/understanding-management-role-groups-exchange-2013-help?view=exchserver-2019

Check Contents

Check the EDSP to verify who should be in each built in RBAC management role group.

If this is not found, this is a finding.

Vulnerability Number

V-259631

Documentable

False

Rule Version

EX19-ED-000174

Severity Override Guidance

Check the EDSP to verify who should be in each built in RBAC management role group.

If this is not found, this is a finding.

Check Content Reference

M

Target Key

5579