Authentication Failure Details Secure string passed to powershell was invalid or empty. Supportive Information The following resource is also helpful. https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2013_Y21M01_STIG.zip This...
DISA_STIG_Microsoft_Exchange_2013_Edge_Transport_Server_v1r5.audit from DISA MS Exchange 2013 Edge Transport Server v1r5 STIG Details NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance. Supportive Information...
EX13-EG-000075 – The Exchange local machine policy must require signed scripts. Details Scripts, especially those downloaded from untrusted locations, often provide a way for attackers to infiltrate a system. By setting...
EX13-EG-000080 – Exchange Internet-facing Send connectors must specify a Smart Host. Details When identifying a ‘Smart Host’ for the email environment, a logical Send connector is the preferred method. A Smart...
EX13-EG-000090 – Exchange Internet-facing Receive connectors must offer Transport Layer Security (TLS) before using basic authentication. Details Sending unencrypted email over the Internet increases the risk that messages can be intercepted or altered. TLS is designed...
EX13-EG-000005 – Exchange must limit the Receive connector timeout. Details Email system availability depends in part on best practices strategies for setting tuning. This configuration controls the number of...
EX13-EG-000095 – Exchange Outbound Connection Timeout must be 10 minutes or less. Details Email system availability depends in part on best practice strategies for setting tuning configurations. This configuration controls the number...
EX13-EG-000010 – Exchange servers must use approved DoD certificates. Details To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DoD-approved...
EX13-EG-000015 – Exchange must have accepted domains configured. Details Exchange may be configured to accept email for multiple domain names. This setting identifies the domains for which the...
EX13-EG-000025 – Exchange external Receive connectors must be domain secure-enabled. Details The Simple Mail Transfer Protocol (SMTP) connector is used by Exchange to send and receive messages from server to...