Information
This policy setting controls whether Outlook decodes encrypted messages itself or passes them to an external program for processing.
If the option Handle internally is selected, Outlook decrypts all S/MIME messages itself.
The recommended state for this setting is: Enabled: Handle internally
This setting could allow unauthorized and potentially dangerous programs to handle encrypted messages outside of the organization, which could compromise security.
Solution
To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Handle internally :
Microsoft Outlook 2016\Security\Cryptography\S/MIME interoperability with external clients
Impact:
The recommended configuration for this setting is Handle internally which enforces the default configuration in Outlook and is unlikely to cause usability issues for most users.
In some situations, administrators might wish to use an external program, such as an add-in, to handle S/MIME message decryption. If a designated external program needed to handle S/MIME messages, an exception to this recommendation must be made.