2.10 Set 'Configure startup mode' to 'TLS'

Information

Use this setting to start the UM Server in secure mode. This forces all dial plans to use TLS.

Rationale:

Communications between other VOIP systems and Exchange that are not protected by TLS are vulnerable to being captured by a malicious third party.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-UMService -Identity Exchange1 -UMStartUpMode TLS

See Also

https://workbench.cisecurity.org/files/1514

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: bd21569bfb2eda4e13a2f6a343e9d1c92eeb0d6cfd73891c58d84d112e61b5bb