1.8 Set 'External send connector authentication: Ignore Start TLS' to 'False'

Information

If this setting is enabled then you will not be able to configure mutual authentication TLS, referred to as 'External send connector authentication: Domain Security' in this baseline.

Rationale:

Basic authentication sends credentials across the network in plaintext. TLS helps protect credentials from interception by unauthorized users.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

set-SendConnector -identity -IgnoreSTARTTLS: $false

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 430dd2370c7b859bd99407c84ee8af744b1ef8a4e2281c5e3c88c7e456c4b582