1.13 Set 'Message tracking logging - Transport' to 'True'

Information

A message tracking log provides a detailed log of all message activity as messages are transferred to and from a computer running Exchange. Message tracking is available on Hub Transport servers, Edge Transport servers, and Mailbox servers. By default, message tracking is enabled.

Rationale:

If events are not recorded it may be difficult or impossible to determine the root cause of system problems or the unauthorized activities of malicious users.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-TransportService EXCHANGE1 -MessageTrackingLogEnabled $true

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Windows

Control ID: 53ecfaca0c85706f04d0f2bdbda1667446c752c033e4958ce27ffb0bb0073ef3