2.5.14.3.19 (L1) Ensure 'Enable RPC encryption' is set to 'Enabled'

Information

This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers.

If this policy setting is enabled, Outlook uses RPC encryption when communicating with an Exchange server.

NOTE: RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet.

The recommended state for this setting is: Enabled

By default, the remote procedure call (RPC) communication channel between an Outlook client computer and an Exchange server is encrypted. If this policy is disabled, an end user may modify this setting creating an opportunity for malicious eavesdropping of network traffic between Outlook client and the Exchange server.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Enable RPC encryption

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

This is the default behavior and would only impact unsupported versions of Outlook.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 0e9f9f7b1163301136086f4d3e58e0f68683f691b318d9237bee7e41c4090e3c