1.11 Ensure 'Exchange recipient filter' is set to 'True'

Information

This policy setting specifies whether the Recipient Filter agent is enabled on the system. The recipient filter uses a recipient block list to identify messages that aren't allowed to enter the organization. The recipient filter also uses the local recipient directory to reject messages sent to invalid recipients.

Rationale:

Spam consumes a large amount of network bandwidth and server capacity. In addition, it is often the source of malicious software. Rejecting messages that have evidence of spoofing will reduce the possibility of users falling victim to phishing attacks.

Impact:

Legitimate email could be blocked by the agent.

Note: The recipient Filter agent is available on Mailbox servers, but it shouldn't be configured. When recipient filtering on a Mailbox server detects one invalid or blocked recipient in a message that contains other valid recipients, the message is rejected.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-RecipientFilterConfig -Enabled $true

Default Value:

True

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8(2)

Plugin: Windows

Control ID: b4d7c4dc144f981b43ba92a9364235e267f0696650bd12af4c8e57d82bb7336d