# Exchange

![](https://2434432314-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCTly3knsVr9zUXbWG1eo%2Fuploads%2FKEcUSxSb2EyMCDOK8orA%2Fexchange%20logo.png?alt=media\&token=f3c89e15-34d0-4f65-b694-e91c35923c29)

**Section Purpose:** The security section shows recommend security controls for Teams based on the CIS Controls. Each control contains the following subsections:

* Description
* Policy Definition
* Licensing Considerations&#x20;
* Set Up Instructions
* End-User Impact
* PowerShell Scripts
* Video Tutorials

| Policy                                                                                                                                                                                                                                      | End-User Impact                                                   | License                                                         |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- | --------------------------------------------------------------- |
| [automatic-forwarding-to-external-domains-shall-be-disabled](https://docs.tminus365.com/security/exchange/automatic-forwarding-to-external-domains-shall-be-disabled "mention")                                                             | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [sender-policy-framework-shall-be-enabled](https://docs.tminus365.com/security/exchange/sender-policy-framework-shall-be-enabled "mention")                                                                                                 | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [domainkeys-identified-mail-should-be-enabled](https://docs.tminus365.com/security/exchange/domainkeys-identified-mail-should-be-enabled "mention")                                                                                         | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [domain-based-message-authentication-reporting-and-conformance-shall-be-enabled](https://docs.tminus365.com/security/exchange/domain-based-message-authentication-reporting-and-conformance-shall-be-enabled "mention")                     | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
|                                                                                                                                                                                                                                             |                                                                   |                                                                 |
| [enable-email-encryption](https://docs.tminus365.com/security/exchange/enable-email-encryption "mention")                                                                                                                                   | <mark style="background-color:green;">Low</mark>                  | Azure Information Protection Plan 1/Business Premium/Enterprise |
| [simple-mail-transfer-protocol-authentication-shall-be-disabled](https://docs.tminus365.com/security/exchange/simple-mail-transfer-protocol-authentication-shall-be-disabled "mention")                                                     | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [calendar-and-contact-sharing-shall-be-restricted](https://docs.tminus365.com/security/exchange/calendar-and-contact-sharing-shall-be-restricted "mention")                                                                                 | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [external-sender-warnings-shall-be-implemented](https://docs.tminus365.com/security/exchange/external-sender-warnings-shall-be-implemented "mention")                                                                                       | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [data-loss-prevention-solutions-shall-be-enabled](https://docs.tminus365.com/security/exchange/data-loss-prevention-solutions-shall-be-enabled "mention")                                                                                   | <mark style="color:yellow;background-color:yellow;">Medium</mark> | Business Premium/Enterprise                                     |
| [emails-shall-be-filtered-by-attachment-file-type](https://docs.tminus365.com/security/exchange/emails-shall-be-filtered-by-attachment-file-type "mention")                                                                                 | <mark style="background-color:green;">Low</mark>                  | Defender for Office 365                                         |
| [zero-hour-auto-purge-for-malware-should-be-enabled](https://docs.tminus365.com/security/exchange/zero-hour-auto-purge-for-malware-should-be-enabled "mention")                                                                             | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [phishing-protections-should-be-enabled](https://docs.tminus365.com/security/exchange/phishing-protections-should-be-enabled "mention")                                                                                                     | <mark style="color:yellow;background-color:yellow;">Medium</mark> | Defender for Office 365                                         |
| [inbound-anti-spam-protections-shall-be-enabled](https://docs.tminus365.com/security/exchange/inbound-anti-spam-protections-shall-be-enabled "mention")                                                                                     | <mark style="color:yellow;background-color:yellow;">Medium</mark> | Standard                                                        |
| [safe-link-policies-should-be-enabled](https://docs.tminus365.com/security/exchange/safe-link-policies-should-be-enabled "mention")                                                                                                         | <mark style="color:yellow;background-color:yellow;">Medium</mark> | Defender for Office 365                                         |
| [safe-attachments-shall-be-enabled](https://docs.tminus365.com/security/exchange/safe-attachments-shall-be-enabled "mention")                                                                                                               | <mark style="color:yellow;background-color:yellow;">Medium</mark> | Defender for Office 365                                         |
| [ip-allow-lists-should-not-be-implemented](https://docs.tminus365.com/security/exchange/ip-allow-lists-should-not-be-implemented "mention")                                                                                                 | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
| [mailbox-auditing-shall-be-enabled](https://docs.tminus365.com/security/exchange/mailbox-auditing-shall-be-enabled "mention")                                                                                                               | <mark style="background-color:green;">None</mark>                 | Standard                                                        |
| [alerts-shall-be-enabled](https://docs.tminus365.com/security/exchange/alerts-shall-be-enabled "mention")                                                                                                                                   | <mark style="background-color:green;">None</mark>                 | Defender for Office 365                                         |
| [audit-logging-shall-be-enabled](https://docs.tminus365.com/security/exchange/audit-logging-shall-be-enabled "mention")                                                                                                                     | <mark style="background-color:green;">None</mark>                 | Standard                                                        |
| [enhanced-filtering-shall-be-configured-if-a-3rd-party-email-filtering-tool-is-being-used](https://docs.tminus365.com/security/exchange/enhanced-filtering-shall-be-configured-if-a-3rd-party-email-filtering-tool-is-being-used "mention") | <mark style="background-color:green;">Low</mark>                  | Standard                                                        |
