Exchange Server 2003 Hardening Guide
Posted on 2004-10-19
Am using the Exchange Server 2003 Hardening Guide to tighten down security on my Exchange servers. Under "Exchange Domain Controller Baseline Policy" in the guide, the second paragraph states:
"The Exchange Domain Controller Baseline Policy template (Exchange 2003 DC Incremental.inf) is included with this guide. You shuold import this template into a Group Policy object (GPO) at the Domain Controllers organizational unit in Active Directory Users and Computers and shold precede the Domain Controller Baseline Policy supplied by Windows Server 2003."
Now, if the Incremental policy is applied first and then the DC Baseline policy, the Domain Baseline policy will win out when it comes to conflicts in the policies, yes?
Looking at the Audit Policy for both policies I see that the DC Baseline policy calls for:
Account logon event auditing: Success/Failure
Logon event auditing: Success Failure
The Audit policy for the Exchange Incremental is set to:
Account Logon event auditing: Failure
Logon event auditing: Failure
Should not the Exchange 2003 DC Incremental policy come after the DC Baseline policy so that the Exchange 2003 DCI changes take and are not displaced?