2.5.1.3 Ensure Mail Summarization Is Disabled

Information

Apple Intelligence's Mail summarization feature uses AI to quickly condense long emails or entire email threads into a few key sentences or bullet points. It automatically appears as a short summary under emails in your inbox, or you can manually tap a "Summarize" button within an open email to get a more detailed overview of complex messages and conversations, helping you grasp the main points at a glance without reading everything.

If there's any concern that your sensitive email content, even if for summarization, might potentially be routed to this third-party service (even with consent prompts), or if you want to avoid any possibility of Apple's servers processing data from highly confidential communications (even within PCC's strong safeguards), disabling the feature ensures your mail content is processed via approved organizational services and on managed devices. This prioritizes absolute control and minimizes any external processing risk for highly sensitive information.

Solution

Profile Method:

Create or edit a configuration profile with the following information:

- The PayloadType string is com.apple.applicationaccess
- The key to include is allowMailSummary
- The key must be set to <false/>

Impact:

The user will no longer see automatic short summaries beneath emails or have the option to generate them on demand.

See Also

https://workbench.cisecurity.org/benchmarks/19972

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|AC-20(1), 800-53|AC-20(2), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1, CSCv7|9.2

Plugin: Unix

Control ID: 7b27aa7d757cebbb27ebe547f46261d7b0da8d40e2dd253e1bdc0e1748a1893c