2.3.4 Ensure 'Enable automatic forwards to remote domains' is set to 'False'

Information

This policy setting is used to determine if the server can send automatic forwards to remote domains.

Rationale:

Data leakage can occur if an email with sensitive data is forwarded to an account that is not secure or sanctioned by the organization.

Impact:

Remote users will not receive automated forward messages.

Note: If Microsoft Exchange is being used as HUB, this setting is applicable. If not, an exception to this recommendation might be required.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-RemoteDomain 'RemoteDomain' -AutoForwardEnabled $false

Default Value:

False

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: ba5df1deaf13ac586c7f5643a3207eb5bbcae071d1b4d4bf6e1aeab6c41909e4