Authentication Failure Details Secure string passed to powershell was invalid or empty. Supportive Information The following resource is also helpful. https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2013_Y21M01_STIG.zip This...
DISA_STIG_Microsoft_Exchange_2013_Client_Access_Server_v1r3.audit from DISA MS Exchange 2013 Client Access Server v1r3 STIG Details NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance. Supportive Information...
EX13-CA-000045 – Exchange Email Diagnostic log level must be set to lowest level. Details Log files help establish a history of activities, and can be useful in detecting attack attempts or determining tuning...
EX13-CA-000050 – Exchange must have Audit record parameters set. Details Log files help establish a history of activities, and can be useful in detecting attack attempts. This item declares...
EX13-CA-000055 – Exchange must have Queue monitoring configured with threshold and action. Details Monitors are automated ‘process watchers’ that respond to performance changes, and can be useful in detecting outages and alerting...
EX13-CA-000005 – Exchange must use Encryption for RPC client access. Details This setting controls whether client machines are forced to use secure channels to communicate with the server. If this...
EX13-CA-000010 – Exchange must use Encryption for OWA access. Details This setting controls whether client machines should be forced to use secure channels to communicate with this virtual directory....
EX13-CA-000015 – Exchange must have Forms-based Authentication disabled. Details Identification and Authentication provide the foundation for access control. Access to email services applications in the DoD requires authentication...
EX13-CA-000020 – Exchange must have authenticated access set to Integrated Windows Authentication only. Details To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DoD-approved...
EX13-CA-000025 – Exchange must have Administrator audit logging enabled. Details Unauthorized or malicious data changes can compromise the integrity and usefulness of the data. Automated attacks or malicious users...