2.3.5 Ensure 'Enable S/MIME for OWA' is set to 'True'

Information

This policy setting is used to control whether users are allowed to download the Secure/Multipurpose Internet Mail Extensions (S/MIME) control to read and create signed and encrypted messages.

Rationale:

S/MIME uses digital signatures and encryption to protect against several classes of attacks including eavesdropping, impersonation, and tampering.

Impact:

Users will be able to use the S/MIME control when accessing their e-mail via OWA.

This is the default value.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-OWAVirtualDirectory 'owa (Default Web Site)' -SMimeEnabled $true

Default Value:

True

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: 3be4bf221cc09ade4727706204d012c3d339b8b0daf6d45be5df16d3b8ca1841