SV-259655r960882_rule
V-259655
SRG-APP-000090
EX19-MB-000034
CAT II
10
Refer to the EDSP on who should have the RBAC role "Audit Log". If a custom RBAC role is designated for the Audit Log role, ensure that the custom RBAC role group is populated.
Follow the rule of least privilege.
Otherwise, in an Exchange management shell, run the following:
"Add-RoleGroupMember -Identity "Records Management" -Member <user>"
Where <user> is the personnel responsible for handling audit logs.
Refer to the EDSP on who should be in the RBAC role group "Audit Log". It is automatically assigned to those in the Organization Management role group.
In an Exchange management shell, run the following cmdlet:
Get-RoleGroup "Records Management"|Get-RoleGroupMember
Unless specified in the EDSP that custom role group is specified for this permission, if this role group is empty this is a finding.
V-259655
False
EX19-MB-000034
Refer to the EDSP on who should be in the RBAC role group "Audit Log". It is automatically assigned to those in the Organization Management role group.
In an Exchange management shell, run the following cmdlet:
Get-RoleGroup "Records Management"|Get-RoleGroupMember
Unless specified in the EDSP that custom role group is specified for this permission, if this role group is empty this is a finding.
M
5580