Skip to content

Microsoft Exchange 2016 Mailbox Server Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000247

    Group
  • The Exchange global inbound message size must be controlled.

    Email system availability depends in part on best practice strategies for setting tuning configurations. Message size limits should be set to 10 megabytes (MB) at most but often are smaller, depend...
    Rule Low Severity
  • SRG-APP-000247

    Group
  • SRG-APP-000247

    Group
  • The Exchange Outbound Connection Limit per Domain Count must be controlled.

    Email system availability depends in part on best practice strategies for setting tuning configurations. This configuration controls the maximum number of simultaneous outbound connections from a d...
    Rule Low Severity
  • SRG-APP-000247

    Group
  • SRG-APP-000261

    Group
  • Exchange Internal Receive connectors must not allow anonymous connections.

    This control is used to limit the servers that may use this server as a relay. If a Simple Mail Transport Protocol (SMTP) sender does not have a direct connection to the Internet (for example, an a...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • Exchange must have anti-spam filtering installed.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. A ...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • Exchange must have anti-spam filtering enabled.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. A ...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • Exchange must have anti-spam filtering configured.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. A ...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • Exchange must not send automated replies to remote domains.

    Attackers can use automated messages to determine whether a user account is active, in the office, traveling, and so on. An attacker might use this information to conduct future attacks. Remote use...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • SRG-APP-000295

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules