2.1.5 Ensure 'Keep deleted mailboxes for the specified number of days' is set to '30'

Information

This policy setting specifies how long deleted mailboxes are retained before they are permanently removed from the database.

Rationale:

Defining a reasonable retention period facilitates recovering accidentally or deliberately deleted mailboxes while controlling the volume of storage that retained mailboxes require.

Impact:

None - This is the default behavior.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-Mailboxdatabase 'Mailbox Database' -MailboxRetention 30.00:00:00

OR

Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Servers' on the left and click on the 'Databases' tab.

Double-click the database and go to the 'Limits' settings.

Change Keep deleted mailboxes for (days): to 30 and click Save.

Default Value:

30

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-11, 800-53|SI-12

Plugin: Windows

Control ID: 0f1d083901a1bd222cc6243f65bae050fc8f59b175515d196dc0c6fca65e27cc