STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The RBAC role for audit log management must be defined and restricted.

DISA Rule

SV-259655r960882_rule

Vulnerability Number

V-259655

Group Title

SRG-APP-000090

Rule Version

EX19-MB-000034

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Refer to the EDSP on who should have the RBAC role "Audit Log". If a custom RBAC role is designated for the Audit Log role, ensure that the custom RBAC role group is populated.

Follow the rule of least privilege.

Otherwise, in an Exchange management shell, run the following:

"Add-RoleGroupMember -Identity "Records Management" -Member <user>"

Where <user> is the personnel responsible for handling audit logs.

Check Contents

Refer to the EDSP on who should be in the RBAC role group "Audit Log". It is automatically assigned to those in the Organization Management role group.

In an Exchange management shell, run the following cmdlet:

Get-RoleGroup "Records Management"|Get-RoleGroupMember

Unless specified in the EDSP that custom role group is specified for this permission, if this role group is empty this is a finding.

Vulnerability Number

V-259655

Documentable

False

Rule Version

EX19-MB-000034

Severity Override Guidance

Refer to the EDSP on who should be in the RBAC role group "Audit Log". It is automatically assigned to those in the Organization Management role group.

In an Exchange management shell, run the following cmdlet:

Get-RoleGroup "Records Management"|Get-RoleGroupMember

Unless specified in the EDSP that custom role group is specified for this permission, if this role group is empty this is a finding.

Check Content Reference

M

Target Key

5580