STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Exchange must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.

DISA Rule

SV-259712r961863_rule

Vulnerability Number

V-259712

Group Title

SRG-APP-000516

Rule Version

EX19-MB-000283

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure web ports to be ports 80 and 443, as specified by PPSM standards.

In an Exchange Management Shell, run the following cmdlet on the "Default Web Site":

Set-WebBinding -Name 'Default Web Site' -BindingInformation "127.0.0.1:443:" -PropertyName Port -Value 443

Set-WebBinding -Name 'Default Web Site' -BindingInformation ":443:" -PropertyName Port -Value 443

Note: This does not apply to the Exchange Back End website.

Check Contents

Open a Windows PowerShell Module and enter the following commands:

Get-Website | Select-Object -Property Name

Get-WebBinding -Name <'WebSiteName'> | Format-List

If the Web binding values returned are not on standard port 80 for HTTP connections or port 443 for HTTPS connections, this is a finding.

Note: This is excluding the Exchange Back End website which uses 81/444.

Repeat the process for each website.

Vulnerability Number

V-259712

Documentable

False

Rule Version

EX19-MB-000283

Severity Override Guidance

Open a Windows PowerShell Module and enter the following commands:

Get-Website | Select-Object -Property Name

Get-WebBinding -Name <'WebSiteName'> | Format-List

If the Web binding values returned are not on standard port 80 for HTTP connections or port 443 for HTTPS connections, this is a finding.

Note: This is excluding the Exchange Back End website which uses 81/444.

Repeat the process for each website.

Check Content Reference

M

Target Key

5580