| Checked | Name | Title |
|---|---|---|
| ☐ | SV-259577r960759_rule | SchUseStrongCrypto must be enabled. |
| ☐ | SV-259578r960792_rule | Exchange servers must use approved DOD certificates. |
| ☐ | SV-259579r960801_rule | Exchange must have accepted domains configured. |
| ☐ | SV-259580r960840_rule | Exchange external Receive connectors must be domain secure-enabled. |
| ☐ | SV-259581r960879_rule | The Exchange email diagnostic log level must be set to the lowest level. |
| ☐ | SV-259582r960879_rule | Exchange connectivity logging must be enabled. |
| ☐ | SV-259583r960900_rule | Exchange message tracking logging must be enabled. |
| ☐ | SV-259584r960918_rule | Exchange queue monitoring must be configured with threshold and action. |
| ☐ | SV-259585r960930_rule | Exchange audit data must be protected against unauthorized access (read access). |
| ☐ | SV-259586r960933_rule | Exchange audit data must be protected against unauthorized access for modification. |
| ☐ | SV-259587r960936_rule | Exchange audit data must be protected against unauthorized access for deletion. |
| ☐ | SV-259588r960948_rule | Exchange audit data must be on separate partitions. |
| ☐ | SV-259589r1015762_rule | Exchange local machine policy must require signed scripts. |
| ☐ | SV-259590r960963_rule | Exchange must not send customer experience reports to Microsoft. |
| ☐ | SV-259591r960963_rule | Exchange Send Fatal Errors to Microsoft must be disabled. |
| ☐ | SV-259592r961095_rule | Exchange queue database must reside on a dedicated partition. |
| ☐ | SV-259593r961101_rule | Exchange internet-facing send connectors must specify a Smart Host. |
| ☐ | SV-259594r1043178_rule | Exchange internal send connectors must use domain security (mutual authentication Transport Layer Security). |
| ☐ | SV-259595r1043178_rule | Exchange internet-facing receive connectors must offer Transport Layer Security (TLS) before using basic authentication. |
| ☐ | SV-259596r961152_rule | More than one Edge server must be deployed. |
| ☐ | SV-259597r961155_rule | Exchange Outbound Connection Timeout must be 10 minutes or less. |
| ☐ | SV-259598r961155_rule | Exchange Outbound Connection limit per Domain Count must be controlled. |
| ☐ | SV-259599r961155_rule | Exchange receive connector maximum hop count must be 60. |
| ☐ | SV-259600r961155_rule | Exchange receive connectors must control the number of recipients per message. |
| ☐ | SV-259601r961155_rule | Exchange send connector connections count must be limited. |
| ☐ | SV-259602r961155_rule | Exchange message size restrictions must be controlled on Send connectors. |
| ☐ | SV-259603r961155_rule | Exchange send connectors delivery retries must be controlled. |
| ☐ | SV-259604r961155_rule | Exchange receive connectors must be clearly named. |
| ☐ | SV-259605r961155_rule | Exchange receive connectors must control the number of recipients chunked on a single message. |
| ☐ | SV-259606r961155_rule | The Exchange internet receive connector connections count must be set to default. |
| ☐ | SV-259607r961155_rule | Exchange Message size restrictions must be controlled on receive connectors. |
| ☐ | SV-259608r961161_rule | Active hyperlinks in messages from non .mil domains must be rendered unclickable. |
| ☐ | SV-259609r961161_rule | Exchange messages with a blank sender field must be rejected. |
| ☐ | SV-259610r961161_rule | Exchange messages with a blank sender field must be filtered. |
| ☐ | SV-259611r961161_rule | Exchange filtered messages must be archived. |
| ☐ | SV-259612r961161_rule | The Exchange sender filter must block unaccepted domains. |
| ☐ | SV-259613r961161_rule | Exchange nonexistent recipients must not be blocked. |
| ☐ | SV-259614r961161_rule | The Exchange Sender Reputation filter must be enabled. |
| ☐ | SV-259615r961161_rule | The Exchange Sender Reputation filter must identify the spam block level. |
| ☐ | SV-259616r961161_rule | Exchange Attachment filtering must remove undesirable attachments by file type. |
| ☐ | SV-259617r961161_rule | The Exchange Spam Evaluation filter must be enabled. |
| ☐ | SV-259618r961161_rule | The Exchange Block List service provider must be identified. |
| ☐ | SV-259619r1040909_rule | Exchange messages with a malformed From address must be rejected. |
| ☐ | SV-259620r961161_rule | The Exchange Recipient filter must be enabled. |
| ☐ | SV-259621r961161_rule | The Exchange tarpitting interval must be set. |
| ☐ | SV-259622r961161_rule | Exchange internal Receive connectors must not allow anonymous connections. |
| ☐ | SV-259623r961161_rule | Exchange Simple Mail Transfer Protocol (SMTP) IP Allow List entries must be empty. |
| ☐ | SV-259624r961161_rule | The Exchange Simple Mail Transfer Protocol (SMTP) IP Allow List Connection filter must be enabled. |
| ☐ | SV-259625r961161_rule | The Exchange Simple Mail Transfer Protocol (SMTP) Sender filter must be enabled. |
| ☐ | SV-259626r961161_rule | Exchange must have anti-spam filtering installed. |
| ☐ | SV-259627r961161_rule | Exchange must have anti-spam filtering enabled. |
| ☐ | SV-259628r961161_rule | Exchange must have anti-spam filtering configured. |
| ☐ | SV-259629r961161_rule | Exchange Sender Identification Framework must be enabled. |
| ☐ | SV-259630r1043182_rule | Exchange must limit the Receive connector timeout. |
| ☐ | SV-259631r961353_rule | Role-Based Access Control must be defined for privileged and nonprivileged users. |
| ☐ | SV-259632r1015763_rule | The Exchange application directory must be protected from unauthorized access. |
| ☐ | SV-259633r961461_rule | The Exchange software baseline copy must exist. |
| ☐ | SV-259634r1015764_rule | The Exchange local machine policy must require signed scripts. |
| ☐ | SV-259635r961470_rule | Exchange services must be documented, and unnecessary services must be removed or disabled. |
| ☐ | SV-259636r961587_rule | The Exchange Edge server must point to a trusted list of DNS servers for external and internal resolution. |
| ☐ | SV-259637r961608_rule | Exchange software must be installed on a separate partition from the OS. |
| ☐ | SV-259638r961620_rule | The Exchange SMTP automated banner response must not reveal server details. |
| ☐ | SV-259639r961620_rule | Exchange internal Send connectors must use an authentication level. |
| ☐ | SV-259640r961632_rule | Exchange must provide redundancy. |
| ☐ | SV-259641r961632_rule | Exchange internal Receive connectors must require encryption. |
| ☐ | SV-259642r961632_rule | Exchange internal Send connectors must require encryption. |
| ☐ | SV-259643r961638_rule | Exchange must render hyperlinks from email sources from non-.mil domains as unclickable. |
| ☐ | SV-259644r961683_rule | Exchange must have the most current, approved Cumulative Update (CU) installed. |