STIGQter STIGQter: STIG Summary:

Microsoft Exchange 2016 Mailbox Server Security Technical Implementation Guide

Version: 2

Release: 6 Benchmark Date: 24 Jan 2024

CheckedNameTitle
SV-228354r879526_ruleExchange must have Administrator audit logging enabled.
SV-228355r879530_ruleExchange servers must use approved DoD certificates.
SV-228356r879533_ruleExchange auto-forwarding email to remote domains must be disabled or restricted.
SV-228357r879559_ruleExchange Connectivity logging must be enabled.
SV-228358r879559_ruleThe Exchange Email Diagnostic log level must be set to the lowest level.
SV-228359r879559_ruleExchange Audit record parameters must be set.
SV-228360r879566_ruleExchange Circular Logging must be disabled.
SV-228361r879566_ruleExchange Email Subject Line logging must be disabled.
SV-228362r879566_ruleExchange Message Tracking Logging must be enabled.
SV-228363r879572_ruleExchange Queue monitoring must be configured with threshold and action.
SV-228364r879587_ruleExchange Send Fatal Errors to Microsoft must be disabled.
SV-228365r879576_ruleExchange must protect audit data against unauthorized read access.
SV-228366r879587_ruleExchange must not send Customer Experience reports to Microsoft.
SV-228367r879577_ruleExchange must protect audit data against unauthorized access.
SV-228368r879578_ruleExchange must protect audit data against unauthorized deletion.
SV-228369r879582_ruleExchange Audit data must be on separate partitions.
SV-228370r879584_ruleExchange Local machine policy must require signed scripts.
SV-228371r944805_ruleThe Exchange Internet Message Access Protocol 4 (IMAP4) service must be disabled.
SV-228372r879587_ruleThe Exchange Post Office Protocol 3 (POP3) service must be disabled.
SV-228373r879631_ruleExchange Mailbox databases must reside on a dedicated partition.
SV-228374r879633_ruleExchange Internet-facing Send connectors must specify a Smart Host.
SV-228375r879636_ruleExchange internal Receive connectors must require encryption.
SV-228376r879642_ruleExchange Mailboxes must be retained until backups are complete.
SV-228377r879642_ruleExchange email forwarding must be restricted.
SV-228378r879642_ruleExchange email-forwarding SMTP domains must be restricted.
SV-228379r879650_ruleExchange Mail quota settings must not restrict receiving mail.
SV-228380r879650_ruleExchange Mail Quota settings must not restrict receiving mail.
SV-228381r879650_ruleExchange Mailbox Stores must mount at startup.
SV-228382r879651_ruleExchange Message size restrictions must be controlled on Receive connectors.
SV-228383r879651_ruleExchange Receive connectors must control the number of recipients per message.
SV-228384r879651_ruleThe Exchange Receive Connector Maximum Hop Count must be 60.
SV-228385r879651_ruleExchange Message size restrictions must be controlled on Send connectors.
SV-228386r879651_ruleThe Exchange Send connector connections count must be limited.
SV-228387r879651_ruleThe Exchange global inbound message size must be controlled.
SV-228388r879651_ruleThe Exchange global outbound message size must be controlled.
SV-228389r879651_ruleThe Exchange Outbound Connection Limit per Domain Count must be controlled.
SV-228390r879651_ruleThe Exchange Outbound Connection Timeout must be 10 minutes or less.
SV-228391r879653_ruleExchange Internal Receive connectors must not allow anonymous connections.
SV-228392r879653_ruleExchange external/Internet-bound automated response messages must be disabled.
SV-228393r879653_ruleExchange must have anti-spam filtering installed.
SV-228394r879653_ruleExchange must have anti-spam filtering enabled.
SV-228395r879653_ruleExchange must have anti-spam filtering configured.
SV-228396r879653_ruleExchange must not send automated replies to remote domains.
SV-228397r879653_ruleExchange servers must have an approved DoD email-aware virus protection software installed.
SV-228398r879653_ruleThe Exchange Global Recipient Count Limit must be set.
SV-228399r879673_ruleThe Exchange Receive connector timeout must be limited.
SV-228400r879751_ruleThe Exchange application directory must be protected from unauthorized access.
SV-228401r879753_ruleAn Exchange software baseline copy must exist.
SV-228402r928977_ruleExchange software must be monitored for unauthorized changes.
SV-228403r879756_ruleExchange services must be documented and unnecessary services must be removed or disabled.
SV-228404r879764_ruleExchange Outlook Anywhere clients must use NTLM authentication to access email.
SV-228405r879802_ruleThe Exchange Email application must not share a partition with another application.
SV-228406r879806_ruleExchange must not send delivery reports to remote domains.
SV-228407r879806_ruleExchange must not send nondelivery reports to remote domains.
SV-228408r879806_ruleThe Exchange SMTP automated banner response must not reveal server details.
SV-228409r879806_ruleExchange Internal Send connectors must use an authentication level.
SV-228410r879806_ruleExchange must provide Mailbox databases in a highly available and redundant configuration.
SV-228411r879827_ruleExchange must have the most current, approved service pack installed.
SV-228412r879887_ruleThe application must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-228413r879664_ruleThe applications built-in Malware Agent must be disabled.
SV-228415r879519_ruleExchange must use encryption for RPC client access.
SV-228416r879519_ruleExchange must use encryption for Outlook Web App (OWA) access.
SV-228417r879519_ruleExchange must have forms-based authentication disabled.
SV-228418r879530_ruleExchange must have authenticated access set to Integrated Windows Authentication only.