3.2 Ensure 'Allow unmanaged devices' is set to 'False'

Information

This policy setting determines whether Exchange will allow devices that do not accept security policy updates from the Exchange server to use ActiveSync.

Rationale:

Unmanaged devices are more likely to not comply with an organization's security policies and to be infected by malicious software.

Impact:

Users who configure their devices to block security policy or have devices that cannot receive security policy will be unable to use ActiveSync to connect to the server.

Note: This is a mobile device management setting. Use caution when applying these settings as they could have adverse effects depending on the environment, and internal policies around bring your own device (BYOD). These policies could affect a user's BYOD.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MobileDeviceMailboxPolicy 'Profile' -AllowNonProvisionableDevices $false

OR

Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Mobile' on the left and click on the 'Mobile device mailbox policies' tab.

Double-click the policy you wish to modify and go to the 'General' settings.

Ensure the Allow mobile devices that don't fully support these policies to synchronize box is not checked and click Save.

Default Value:

False

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-17, 800-53|AC-17(1), 800-53|SC-7, 800-53|SI-4, CSCv7|12.12

Plugin: Windows

Control ID: cbca5cffc684947b737c3e087fd6722111416aa3253c72e7ea5414bdc5c72aea