Information
This policy setting is used to determine if the server automatically forwards out-of-office messages to remote domains.
Rationale:
Attackers can use automated messages to determine whether a user is active, in the office, traveling, and so on. An attacker might use this information to conduct other types of attacks.
Impact:
Remote users will not receive automated out-of-office messages.
Solution
To implement the recommended state, execute the following PowerShell cmdlet:
Set-RemoteDomain 'RemoteDomain' -AllowedOOFType None
Default Value:
External