MS.EXO.5.1v1 - SMTP AUTH SHALL be disabled.

Information

SMTP AUTH is not used or needed by modern email clients. Therefore, disabling it as the global default conforms to the principle of least functionality.

Solution

To disable SMTP AUTH for the organization:

1. Sign in to the Exchange admin center.

2. On the left hand pane, select Settings; then from the settings list, select Mail Flow.

3. Make sure the setting Turn off SMTP AUTH protocol for your organization is checked.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: microsoft_azure

Control ID: 1654de8efbda8ac12d2eb8d97d9b1a23d98a508193651f6bca83aad2b8b15afe