2.5.14.3.30 (L1) Ensure 'Signature Warning' is set to 'Enabled: Always warn about invalid signatures'

Information

This policy setting controls how Outlook warns users about messages with invalid digital signatures.

The recommended state for this setting is: Enabled: Always warn about invalid signatures

If users are not notified about invalid signatures, it might prevent the user from detecting a fraudulent signature sent by a malicious user.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Always warn about invalid signatures :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Signature Warning

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

None - This is the default behavior.

Enabling this setting could cause some disruptions for Outlook users who receive a lot of e-mail messages signed with invalid signatures. These users will see a warning dialog box every time they open a signed e-mail message.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Windows

Control ID: 800669b1fd9806313a3e0e38e315eca47e4d55ac42ee1f9ecbb6e5acfe72122c