The Exchange local machine policy must require signed scripts.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-221216SRG-APP-000131EX16-ED-000150SV-221216r960954_rule2024-12-062
Description
Scripts, especially those downloaded from untrusted locations, often provide a way for attackers to infiltrate a system. By setting machine policy to prevent unauthorized script executions, unanticipated system impacts can be avoided.
ℹ️ Check
Open the Exchange Management Shell and enter the following command: Get-ExecutionPolicy If the value returned is not "RemoteSigned", this is a finding.
✔️ Fix
Open the Exchange Management Shell and enter the following command: Set-ExecutionPolicy RemoteSigned