1.15 Set 'Configure login authentication for IMAP4' to 'SecureLogin'

Information

IMAP4 transmits all data, including user credentials and potentially sensitive messages, in plaintext. Using this setting to enable SSL ensures that IMAP4 network traffic is encrypted, and it allows the client to verify the server's address.

Rationale:

An attacker who can intercept or eavesdrop on the IMAP4 traffic could view sensitive information.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-ImapSettings -LOGINTYPE SECURELOGIN

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Windows

Control ID: f64f70abc168cb0061e5e2a10c06efa061b930f61fba9b230f45dcfaf5ca3fcb