STIGQter STIGQter: STIG Summary: Exchange 2010 Client Access Server STIG Version: 1 Release: 9 Benchmark Date: 27 Jan 2017:

The Microsoft Active Sync directory must be removed.

DISA Rule

SV-44030r1_rule

Vulnerability Number

V-33610

Group Title

Exch-1-603

Rule Version

Exch-1-603

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Open an Exchange Command Shell and enter the following command:

Remove-ActiveSyncVirtualDirectory ServerName\Microsoft-Server-Active-Sync -Confirm $true

NOTE: The physical directory must also be deleted.

Check Contents

Open the Exchange Management Shell and enter the following command:

Get-ActiveSyncVirtualDirectory | Select Server, Name, Identity, Path

If the value of 'Path' (actual directory) exists, this is a finding.

Vulnerability Number

V-33610

Documentable

False

Rule Version

Exch-1-603

Severity Override Guidance

Open the Exchange Management Shell and enter the following command:

Get-ActiveSyncVirtualDirectory | Select Server, Name, Identity, Path

If the value of 'Path' (actual directory) exists, this is a finding.

Check Content Reference

M

Target Key

1995

Comments