1.18 Set 'Maximum receive size - connector level' to '10240'

Information

You can use this setting to limit the total size of messages at the connector level. This includes the message header, the message body, and any attachments. For internal message flow, Exchange Server uses the custom X-MS-Exchange-Organization-OriginalSize message header to record the original message size of the message as it enters the Exchange Server organization. Whenever the message is checked against the specified message size limits, the lower value of the current message size or the original message size header is used. The size of the message can change because of content conversion, encoding, and agent processing.

Rationale:

This setting somewhat limits the impact a malicious user or a computer with malware can have on the Exchange infrastructure by restricting the size of incoming messages.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-ReceiveConnector 'Connection from Contoso.com' -MaxMessageSize 10240KB

See Also

https://workbench.cisecurity.org/files/1514

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Windows

Control ID: 67cc12d2f150039293b79772347c9282e273dc1e6caf31d9b0516b6be52ad269