1.9 Set 'Configure login authentication for POP3' to 'SecureLogin'

Information

POP3 transmits all data, including user credentials and potentially sensitive messages, in plaintext. Using this setting to enable TLS ensures that POP3 network traffic is encrypted, and it allows the client to verify the server's address.

Rationale:

An attacker who can intercept or eavesdrop on the POP3 traffic could view sensitive information.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-PopSettings -LoginType SecureLogin

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Windows

Control ID: 735973ac3cf109a0e3e516b53420260be994bd3e5c6098236feccfb9820d3bf1