2.5.14.2.2 (L1) Ensure 'Do not display 'Publish to GAL' button' is set to 'Enabled'

Information

This policy setting controls whether Outlook users can publish e-mail certificates to the Global Address List (GAL). The GAL contains information for all email users, distribution groups, and Exchange resources.

The recommended state for this setting is: Enabled

Only Administrators should be able to perform tasks such as publishing digital certificates to the GAL.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Outlook 2016\Security\Cryptography\Do not display 'Publish to GAL' button

Impact:

Only Administrators will be able to publish a new or updated certificate to the GAL.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 75ca5179f7a03806e5384773697c12b83a06b6aaa7743d31ea149a8eb3b5f0c6