2.5.14.2.5 (L1) Ensure 'S/MIME interoperability with external clients:' is set to 'Enabled: Handle internally'

Information

This policy setting controls whether Outlook decodes encrypted messages itself or passes them to an external program for processing.

If the option Handle internally is selected, Outlook decrypts all S/MIME messages itself.

The recommended state for this setting is: Enabled: Handle internally

This setting could allow unauthorized and potentially dangerous programs to handle encrypted messages outside of the organization, which could compromise security.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Handle internally :

Microsoft Outlook 2016\Security\Cryptography\S/MIME interoperability with external clients

Impact:

The recommended configuration for this setting is Handle internally which enforces the default configuration in Outlook and is unlikely to cause usability issues for most users.

In some situations, administrators might wish to use an external program, such as an add-in, to handle S/MIME message decryption. If a designated external program needed to handle S/MIME messages, an exception to this recommendation must be made.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Windows

Control ID: aa59cc9eebb8eb07b479902aad38e39581452115ce1a77080a9fbee2e0b1005b