1.8 Set 'External send connector authentication: Ignore Start TLS' to 'False'

Information

If this setting is enabled then you will not be able to configure mutual authentication TLS, referred to as 'External send connector authentication: Domain Security' in this baseline.

Rationale:

Basic authentication sends credentials across the network in plaintext. TLS helps protect credentials from interception by unauthorized users.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

set-SendConnector -identity -IgnoreSTARTTLS: $false

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 662de5b05369dddd3979ca87147aeab3953fd092f6b4c366fc28ce249164b78f