2.1.4 Ensure 'Mailbox quotas: Prohibit send at' is set to ''

Information

This policy setting can automatically prevent users from sending new e-mail messages after their mailboxes reach a specified limit. It's suggested that this warning be set up when 95% of the mailbox size has been reached. For example, if the mailbox size is 100 GB, set the warning to 95 GB or 99,614,720 KB.

A value between 0 and 2,147,483,647 KB (2.1 terabytes) can be set depending on the user's mailbox size.

Rationale:

Unlimited mailbox sizes can cause the Exchange database to grow uncontrollably and consume all available disk space, potentially preventing the database from mounting properly. This can disrupt not only email services but also other security measures that depend on timely communication.

Impact:

Users will be unable to send messages when their mailboxes reach the specified value.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MailboxDatabase 'Mailbox Database' -ProhibitSendQuota <value>

OR

Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Servers' on the left and click on the 'Databases' tab.

Double-click the database and go to the 'Limits' settings.

Change Prohibit send at (GB): to <value> and click Save.

Default Value:

2 GB (2,147,483,648 bytes)

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-6

Plugin: Windows

Control ID: d59749e047b1ac4053425417809b82eceef0826c30cdf720b1103c3d81186bce