Authentication Failure Details Secure string passed to powershell was invalid or empty. Supportive Information The following resource is also helpful. https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2016_Y21M07_STIG.zip This...
DISA_STIG_Microsoft_Exchange_2016_Edge_Transport_Server_v2r2.audit from DISA Microsoft Exchange 2016 Edge Transport Server v2r2 STIG Details NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance. Supportive Information...
EX16-ED-000140 – Exchange audit data must be on separate partitions. Details Log files help establish a history of activities and can be useful in detecting attack attempts or determining tuning...
EX16-ED-000150 – The Exchange local machine policy must require signed scripts. Details Scripts, especially those downloaded from untrusted locations, often provide a way for attackers to infiltrate a system. By setting...
EX16-ED-000160 – Exchange Internet-facing Send connectors must specify a Smart Host. Details When identifying a ‘Smart Host’ for the email environment, a logical Send connector is the preferred method. A Smart...
EX16-ED-000010 – Exchange must limit the Receive connector timeout. Details Email system availability depends in part on best practices strategies for setting tuning. This configuration controls the number of...
EX16-ED-000170 – Exchange internal Send connectors must use domain security (mutual authentication Transport Layer Security). Details The Simple Mail Transfer Protocol (SMTP) connector is used by Exchange to send and receive messages from server to...
EX16-ED-000020 – Exchange servers must use approved DoD certificates. Details To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DoD-approved...
EX16-ED-000180 – Exchange Internet-facing Receive connectors must offer Transport Layer Security (TLS) before using basic authentication. Details Sending unencrypted email over the Internet increases the risk that messages can be intercepted or altered. TLS is designed...
EX16-ED-000030 – Exchange must have accepted domains configured. Details Exchange may be configured to accept email for multiple domain names. This setting identifies the domains for which the...