DISA Microsoft Exchange 2019 Edge Server STIG v2r2

Audit Details

Name: DISA Microsoft Exchange 2019 Edge Server STIG v2r2

Updated: 1/22/2026

Authority: DISA STIG

Plugin: Windows

Revision: 1.1

Estimated Item Count: 69

File Details

Filename: DISA_Microsoft_Exchange_2019_Edge_Server_STIG_v2r2.audit

Size: 160 kB

MD5: 709a699a313804828be8017cf163d572
SHA256: 82c97a5a60600ed03fa41d1cf862f8490abb79b7d3472ca005cc8746a8116762

Audit Changelog

 
Revision 1.1

Jan 22, 2026

Informational Update
  • EX19-ED-000006 - SchUseStrongCrypto must be enabled.
  • EX19-ED-000026 - The Exchange email diagnostic log level must be set to the lowest level.
  • EX19-ED-000040 - Exchange queue monitoring must be configured with threshold and action.
  • EX19-ED-000055 - Exchange must not send customer experience reports to Microsoft.
  • EX19-ED-000095 - Exchange internet-facing send connectors must specify a Smart Host.
  • EX19-ED-000113 - Exchange receive connectors must control the number of recipients per message.
  • EX19-ED-000118 - Exchange receive connectors must control the number of recipients chunked on a single message.
  • EX19-ED-000126 - The Exchange sender filter must block unaccepted domains.
  • EX19-ED-000133 - Exchange messages with a malformed From address must be rejected.
  • EX19-ED-000135 - The Exchange tarpitting interval must be set.
  • EX19-ED-000224 - The Exchange Edge server must point to a trusted list of DNS servers for external and internal resolution.
  • EX19-ED-000236 - Exchange internal Send connectors must require encryption.
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • See also link updated.
Added
  • DISA_STIG_Microsoft_Exchange_2019_Edge_Server_v2r2.audit from DISA Microsoft Exchange 2019 Edge Server STIG v2r2
Removed
  • DISA_Microsoft_Exchange_2019_Edge_Server_STIG_v2r2.audit from DISA Microsoft Exchange 2019 Edge Server v2r2 STIG