Remediation Steps
Follow the steps below to remediate this finding on Windows.
For Microsoft Exchange, open the Exchange Admin Center.
Go to Mail flow > Receive connectors.
Select each connector and verify the Permission groups do not include Anonymous users for relay.
For IIS SMTP service, open IIS 6 Manager.
Select the SMTP Virtual Server, right-click and select Properties.
On the Access tab, click Relay, and set relay restrictions to allow only specific IP addresses.