2.7 Ensure only the server farm account has access to SharePointEmailws.asmx

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SharePoint 2016 includes an internal service, the Microsoft SharePoint Directory Management Service, for creating e-mail distribution groups. When you configure e-mail integration, you have the option to enable the Directory Management Service feature, which lets users create distribution lists. When users create a SharePoint group and they select the option to create a distribution list, the Microsoft SharePoint Directory Management Service creates the corresponding Active Directory distribution list in the Active Directory environment.
Rationale:
The ability to create distribution lists should be limited to only those accounts that require the ability to create lists. Restricting the accounts that can access SharePointEmailws.asmx accomplishes that.

Solution

1. Locate the SharePointEmailws.asmx file in Windows Explorer
2. Right-click on the file and choose Properties
3. Click on the Security tab
4. Set the permissions so that only the server farm account has read permissions to the file.

See Also

https://www.cisecurity.org/benchmark/microsoft_sharepoint/