1.11 Set send connector 'Configure Protocol logging' to 'Verbose'

Information

A protocol log is a record of the SMTP activity between messaging servers as part of message delivery. This SMTP activity occurs on Send connectors and Receive connectors that are configured on Hub Transport servers and Edge Transport servers. By default, protocol logging is disabled.

Rationale:

If events are not recorded it may be difficult or impossible to determine the root cause of system problems or the unauthorized activities of malicious users.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-SendConnector 'IDENTITY' -ProtocolLoggingLevel Verbose

See Also

https://workbench.cisecurity.org/files/1514

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Windows

Control ID: 0b19011b556a8eb928a6eeee40a75929d5a8caa294cf6c10bd2641579dae76bb