2.1.2 Ensure 'Retain deleted items for the specified number of days' is set to '14'

Information

This policy setting specifies how long deleted messages are retained before they are permanently removed from the database.

Rationale:

Defining a reasonable retention period facilitates recovering accidentally deleted messages while controlling the volume of storage that retained messages require.

Impact:

None - This is the default behavior.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MailboxDatabase 'Mailbox Database' -DeletedItemRetention 14

OR

Perform the following actions:

Launch the EAC (Exchange Administrative Center).

Go to 'Servers' on the left and click on the 'Databases' tab.

Double-click the database and go to the 'Limits' settings.

Change Keep deleted items for (days): to 14 and click Save.

Default Value:

14

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-11, 800-53|SI-12

Plugin: Windows

Control ID: 8e797e92abbcec29214a8cc37fbc803094a29cbf1194404f85963998e0e0de3d