Exchange mail quota settings must not restrict receiving mail.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-259675EX19-MB-000122SV-259675r961152_ruleCCI-001094low
Description
Mail quota settings control the maximum sizes of a user's mailbox and the system's response if these limits are exceeded. Mailbox data that is not monitored against a quota increases the risk of mail loss due to filled disk space, which can also render the system unavailable. Failure to allow mail receipt may impede users from receiving mission-critical data.
STIGDate
Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide2025-05-14

Details

Check Text (C-259675r961152_chk)

Open the Exchange Management Shell and enter the following command: Get-MailboxDatabase | Select-Object -Property Name, Identity, ProhibitSendReceiveQuota If the value of "ProhibitSendReceiveQuota" is not set to "Unlimited", this is a finding. or If the value of "ProhibitSendReceiveQuota" is set to an alternate value and has signoff and risk acceptance in the EDSP, this is not a finding.

Fix Text (F-63322r942338_fix)

Open the Exchange Management Shell and enter the following command: Set-MailboxDatabase -Identity <'IdentityName'> -ProhibitSendReceiveQuota Unlimited Note: The <IdentityName> value must be in quotes. or Enter the value as identified by the EDSP that has obtained a signoff with risk acceptance.