STIGQter STIGQter: STIG Summary:

Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide

Version: 2

Release: 3 Benchmark Date: 02 Jul 2025

CheckedNameTitle
SV-259645r960759_ruleExchange must use encryption for RPC client access.
SV-259646r960759_ruleExchange must use encryption for Outlook Web App (OWA) access.
SV-259647r960759_ruleExchange must have forms-based authentication enabled.
SV-259648r960780_ruleExchange must have administrator audit logging enabled.
SV-259649r960792_ruleExchange servers must use approved DOD certificates.
SV-259650r960792_ruleExchange must have authenticated access set to integrated Windows authentication only.
SV-259651r960801_ruleExchange auto-forwarding email to remote domains must be disabled or restricted.
SV-259652r960879_ruleExchange connectivity logging must be enabled.
SV-259653r960879_ruleThe Exchange email diagnostic log level must be set to the lowest level.
SV-259654r960879_ruleExchange audit record parameters must be set.
SV-259655r960882_ruleThe RBAC role for audit log management must be defined and restricted.
SV-259656r960900_ruleExchange email subject line logging must be disabled.
SV-259657r960900_ruleExchange message tracking logging must be enabled.
SV-259658r960900_ruleExchange circular logging must be disabled.
SV-259659r960918_ruleExchange queue monitoring must be configured with threshold and action.
SV-259660r960930_ruleExchange must protect audit data against unauthorized read access.
SV-259661r960933_ruleExchange must protect audit data against unauthorized access.
SV-259662r960936_ruleExchange must protect audit data against unauthorized deletion.
SV-259663r960948_ruleExchange audit data must be on separate partitions.
SV-259664r1015275_ruleExchange local machine policy must require signed scripts.
SV-259665r960963_ruleExchange Send Fatal Errors to Microsoft must be disabled.
SV-259666r960963_ruleExchange must not send customer experience reports to Microsoft.
SV-259667r960963_ruleThe Exchange Internet Message Access Protocol 4 (IMAP4) service must be disabled.
SV-259668r960963_ruleThe Exchange Post Office Protocol 3 (POP3) service must be disabled.
SV-259669r961095_ruleExchange Mailbox databases must reside on a dedicated partition.
SV-259670r961101_ruleExchange internet-facing send connectors must specify a smart host.
SV-259671r961128_ruleExchange mailboxes must be retained until backups are complete.
SV-259672r961128_ruleExchange email forwarding must be restricted.
SV-259673r961128_ruleExchange email-forwarding SMTP domains must be restricted.
SV-259674r961152_ruleExchange mailbox stores must mount at startup.
SV-259675r961152_ruleExchange mail quota settings must not restrict receiving mail.
SV-259676r961152_ruleExchange mail quota settings must not restrict sending mail.
SV-259677r961155_ruleExchange Message size restrictions must be controlled on Receive connectors.
SV-259678r961155_ruleThe Exchange Receive Connector Maximum Hop Count must be 60.
SV-259679r961155_ruleThe Exchange send connector connections count must be limited.
SV-259681r961155_ruleExchange message size restrictions must be controlled on send connectors.
SV-259682r961155_ruleThe Exchange global inbound message size must be controlled.
SV-259683r961155_ruleThe Exchange global outbound message size must be controlled.
SV-259684r961155_ruleThe Exchange Outbound Connection Limit per Domain Count must be controlled.
SV-259685r961155_ruleThe Exchange Outbound Connection Timeout must be 10 minutes or less.
SV-259686r961161_ruleExchange servers must have an approved DOD email-aware virus protection software installed.
SV-259687r961161_ruleExchange internal receive connectors must not allow anonymous connections.
SV-259688r961161_ruleExchange external/internet-bound automated response messages must be disabled.
SV-259689r961161_ruleExchange must have anti-spam filtering installed.
SV-259690r961161_ruleExchange must have anti-spam filtering enabled.
SV-259691r961161_ruleExchange must have anti-spam filtering configured.
SV-259692r961161_ruleExchange must not send automated replies to remote domains.
SV-259693r961161_ruleThe Exchange Global Recipient Count Limit must be set.
SV-259694r1015276_ruleExchange antimalware agent must be enabled and configured.
SV-259695r1015277_ruleThe Exchange malware scanning agent must be configured for automatic updates.
SV-259697r1043182_ruleThe Exchange receive connector timeout must be limited.
SV-259698r961353_ruleRole-Based Access Control must be defined for privileged and nonprivileged users.
SV-259699r1015278_ruleThe Exchange application directory must be protected from unauthorized access.
SV-259700r961461_ruleAn Exchange software baseline copy must exist.
SV-259701r1015279_ruleExchange software must be monitored for unauthorized changes.
SV-259702r961470_ruleExchange services must be documented, and unnecessary services must be removed or disabled.
SV-259703r961494_ruleExchange Outlook Anywhere clients must use NTLM authentication to access email.
SV-259704r961608_ruleThe Exchange email application must not share a partition with another application.
SV-259705r961620_ruleExchange must not send delivery reports to remote domains.
SV-259706r961620_ruleExchange must not send nondelivery reports to remote domains.
SV-259707r961620_ruleThe Exchange SMTP automated banner response must not reveal server details.
SV-259708r961620_ruleExchange internal send connectors must use an authentication level.
SV-259709r961620_ruleExchange must provide mailbox databases in a highly available and redundant configuration.
SV-259710r961632_ruleThe application must protect the confidentiality and integrity of transmitted information.
SV-259711r961683_ruleExchange must have the most current, approved Cumulative Update installed.
SV-259712r961863_ruleExchange must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.