| Checked | Name | Title |
|---|---|---|
| ☐ | SV-259645r960759_rule | Exchange must use encryption for RPC client access. |
| ☐ | SV-259646r960759_rule | Exchange must use encryption for Outlook Web App (OWA) access. |
| ☐ | SV-259647r960759_rule | Exchange must have forms-based authentication enabled. |
| ☐ | SV-259648r960780_rule | Exchange must have administrator audit logging enabled. |
| ☐ | SV-259649r960792_rule | Exchange servers must use approved DOD certificates. |
| ☐ | SV-259650r960792_rule | Exchange must have authenticated access set to integrated Windows authentication only. |
| ☐ | SV-259651r960801_rule | Exchange auto-forwarding email to remote domains must be disabled or restricted. |
| ☐ | SV-259652r960879_rule | Exchange connectivity logging must be enabled. |
| ☐ | SV-259653r960879_rule | The Exchange email diagnostic log level must be set to the lowest level. |
| ☐ | SV-259654r960879_rule | Exchange audit record parameters must be set. |
| ☐ | SV-259655r960882_rule | The RBAC role for audit log management must be defined and restricted. |
| ☐ | SV-259656r960900_rule | Exchange email subject line logging must be disabled. |
| ☐ | SV-259657r960900_rule | Exchange message tracking logging must be enabled. |
| ☐ | SV-259658r960900_rule | Exchange circular logging must be disabled. |
| ☐ | SV-259659r960918_rule | Exchange queue monitoring must be configured with threshold and action. |
| ☐ | SV-259660r960930_rule | Exchange must protect audit data against unauthorized read access. |
| ☐ | SV-259661r960933_rule | Exchange must protect audit data against unauthorized access. |
| ☐ | SV-259662r960936_rule | Exchange must protect audit data against unauthorized deletion. |
| ☐ | SV-259663r960948_rule | Exchange audit data must be on separate partitions. |
| ☐ | SV-259664r1015275_rule | Exchange local machine policy must require signed scripts. |
| ☐ | SV-259665r960963_rule | Exchange Send Fatal Errors to Microsoft must be disabled. |
| ☐ | SV-259666r960963_rule | Exchange must not send customer experience reports to Microsoft. |
| ☐ | SV-259667r960963_rule | The Exchange Internet Message Access Protocol 4 (IMAP4) service must be disabled. |
| ☐ | SV-259668r960963_rule | The Exchange Post Office Protocol 3 (POP3) service must be disabled. |
| ☐ | SV-259669r961095_rule | Exchange Mailbox databases must reside on a dedicated partition. |
| ☐ | SV-259670r961101_rule | Exchange internet-facing send connectors must specify a smart host. |
| ☐ | SV-259671r961128_rule | Exchange mailboxes must be retained until backups are complete. |
| ☐ | SV-259672r961128_rule | Exchange email forwarding must be restricted. |
| ☐ | SV-259673r961128_rule | Exchange email-forwarding SMTP domains must be restricted. |
| ☐ | SV-259674r961152_rule | Exchange mailbox stores must mount at startup. |
| ☐ | SV-259675r961152_rule | Exchange mail quota settings must not restrict receiving mail. |
| ☐ | SV-259676r961152_rule | Exchange mail quota settings must not restrict sending mail. |
| ☐ | SV-259677r961155_rule | Exchange Message size restrictions must be controlled on Receive connectors. |
| ☐ | SV-259678r961155_rule | The Exchange Receive Connector Maximum Hop Count must be 60. |
| ☐ | SV-259679r961155_rule | The Exchange send connector connections count must be limited. |
| ☐ | SV-259681r961155_rule | Exchange message size restrictions must be controlled on send connectors. |
| ☐ | SV-259682r961155_rule | The Exchange global inbound message size must be controlled. |
| ☐ | SV-259683r961155_rule | The Exchange global outbound message size must be controlled. |
| ☐ | SV-259684r961155_rule | The Exchange Outbound Connection Limit per Domain Count must be controlled. |
| ☐ | SV-259685r961155_rule | The Exchange Outbound Connection Timeout must be 10 minutes or less. |
| ☐ | SV-259686r961161_rule | Exchange servers must have an approved DOD email-aware virus protection software installed. |
| ☐ | SV-259687r961161_rule | Exchange internal receive connectors must not allow anonymous connections. |
| ☐ | SV-259688r961161_rule | Exchange external/internet-bound automated response messages must be disabled. |
| ☐ | SV-259689r961161_rule | Exchange must have anti-spam filtering installed. |
| ☐ | SV-259690r961161_rule | Exchange must have anti-spam filtering enabled. |
| ☐ | SV-259691r961161_rule | Exchange must have anti-spam filtering configured. |
| ☐ | SV-259692r961161_rule | Exchange must not send automated replies to remote domains. |
| ☐ | SV-259693r961161_rule | The Exchange Global Recipient Count Limit must be set. |
| ☐ | SV-259694r1015276_rule | Exchange antimalware agent must be enabled and configured. |
| ☐ | SV-259695r1015277_rule | The Exchange malware scanning agent must be configured for automatic updates. |
| ☐ | SV-259697r1043182_rule | The Exchange receive connector timeout must be limited. |
| ☐ | SV-259698r961353_rule | Role-Based Access Control must be defined for privileged and nonprivileged users. |
| ☐ | SV-259699r1015278_rule | The Exchange application directory must be protected from unauthorized access. |
| ☐ | SV-259700r961461_rule | An Exchange software baseline copy must exist. |
| ☐ | SV-259701r1015279_rule | Exchange software must be monitored for unauthorized changes. |
| ☐ | SV-259702r961470_rule | Exchange services must be documented, and unnecessary services must be removed or disabled. |
| ☐ | SV-259703r961494_rule | Exchange Outlook Anywhere clients must use NTLM authentication to access email. |
| ☐ | SV-259704r961608_rule | The Exchange email application must not share a partition with another application. |
| ☐ | SV-259705r961620_rule | Exchange must not send delivery reports to remote domains. |
| ☐ | SV-259706r961620_rule | Exchange must not send nondelivery reports to remote domains. |
| ☐ | SV-259707r961620_rule | The Exchange SMTP automated banner response must not reveal server details. |
| ☐ | SV-259708r961620_rule | Exchange internal send connectors must use an authentication level. |
| ☐ | SV-259709r961620_rule | Exchange must provide mailbox databases in a highly available and redundant configuration. |
| ☐ | SV-259710r961632_rule | The application must protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-259711r961683_rule | Exchange must have the most current, approved Cumulative Update installed. |
| ☐ | SV-259712r961863_rule | Exchange must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. |