2.3.3 Ensure 'Enable automatic replies to remote domains' is set to 'False'

Information

This policy setting is used to determine if the server automatically replies to remote domains. The AutoReplyEnabled parameter specifies whether to allow messages that are automatic replies from client email programs in an organization (for example, automatic reply messages that are generated by rules in Outlook).

Rationale:

Attackers can use automated messages to determine whether a user is active, in the office, traveling etc. and can use this information to conduct other types of attacks.

Impact:

Remote users will not receive automated replies.

Note: If Microsoft Exchange is being used as HUB, this setting is applicable. If not, an exception to this recommendation might be required.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-RemoteDomain 'RemoteDomain' -AutoReplyEnabled $false

Default Value:

False

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 4c7d3691ba6938629e458e480e64ea8fc7e188238b9691873f780bb7a668fe0f