2.5.14.3.7 (L1) Ensure 'Allow scripts in one-off Outlook forms' is set to 'Disabled'

Information

This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message.

The recommended state for this setting is: Disabled

Malicious code can be included within Outlook forms and can be executed when users open the form.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Allow scripts in one-off Outlook forms

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

None - this is the default behavior. Unless users have a legitimate business need for such functionality, this setting should be disabled.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1)

Plugin: Windows

Control ID: 003698818da301a94417c17768a6c1f1d49ba5ffa3d49219630b71437c5ec949