STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Role-Based Access Control must be defined for privileged and nonprivileged users.

DISA Rule

SV-259698r961353_rule

Vulnerability Number

V-259698

Group Title

SRG-APP-000340

Rule Version

EX19-MB-000173

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Update the EDSP and define which users should and should not have elevated privileges within the organization.

Follow the rule of least privilege and ensure that administrators are given just enough access to complete their job.

Referenced Document: https://docs.microsoft.com/en-us/exchange/understanding-management-role-groups-exchange-2013-help?view=exchserver-2019

Check Contents

Review the Email Domain Security Plan (EDSP) to verify which users should be in each built-in RBAC management role group.

If this is not found, this is a finding.

Vulnerability Number

V-259698

Documentable

False

Rule Version

EX19-MB-000173

Severity Override Guidance

Review the Email Domain Security Plan (EDSP) to verify which users should be in each built-in RBAC management role group.

If this is not found, this is a finding.

Check Content Reference

M

Target Key

5580