2.1.3 Ensure 'Mailbox quotas: Prohibit send and receive at' is set to ''

Information

This policy setting can automatically prevent users from sending and receiving e-mail messages after their mailbox size reaches the specified limit. It's suggested that this warning be set up when 98% of the mailbox size has been reached. For example, if the mailbox size is 100 GB, set the warning to 98 GB or 102,760,448 KB.

A value between 0 and 2,147,483,647 KB (2.1 terabytes) can be set depending on the user's mailbox size.

Rationale:

Unlimited mailbox sizes can cause the Exchange database to grow uncontrollably and consume all available disk space, potentially preventing the database from mounting properly. This can disrupt not only email services but also other security measures that depend on timely communication.

Impact:

Users will be unable to send or receive messages when their mailboxes reach the specified value.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MailboxDatabase 'Mailbox Database' -ProhibitSendReceiveQuota <value>GB

OR

Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Servers' on the left and click on the 'Databases' tab.

Double-click the database and go to the 'Limits' settings.

Change Prohibit send and receive at (GB): to <value>and click Save.

Default Value:

2.3 GB (2,469,396,480 bytes)

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-6

Plugin: Windows

Control ID: 7ea059fc06a2fb1fe520a506efdb234468d5c83972131a40c629fbd712b65470