1.13.9 Ensure 'Prevent users from customizing attachment security settings' is set to Enabled

Information

This policy setting prevents users from overriding the set of attachments blocked by Outlook.
If you enable this policy setting users will be prevented from overriding the set of attachments blocked by Outlook. Outlook also checks the 'Level1Remove' registry key when this setting is specified.
If you disable or do not configure this policy setting, users will be allowed to override the set of attachments blocked by Outlook. The recommended state for this setting is: Enabled.

Rationale:

If users are able to change the security settings for attachments they could choose less secure values and increase the risk of unintentionally spreading malware.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled.

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Prevent users from customizing attachment security settings

Impact:

Enabling this setting cause some users to be frustrated that they cannot customize the attachment security settings, but in most environments this should not be a significant issue.

See Also

https://workbench.cisecurity.org/files/553

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3a.

Plugin: Windows

Control ID: cfd1bafd8f13384bb0d25082616695ac7fb8861c9ad562b30be3e5e09bfc121c