2.5.10.8.4.3 (L1) Ensure 'Trust e-mail from contacts' is set to 'Disabled'

Information

This policy setting controls whether Outlook analyzes email from users' Contacts when filtering junk e-mail.

The recommended state for this setting is: Disabled

E-mail addresses in users' Contacts list are treated as safe senders for purposes of filtering junk email. If a trusted contact's email is hijacked or compromised, the recipient of a spam campaign may become a victim as the email won't receive the same scrutiny from Outlook's junk email filtering.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Outlook 2016\Outlook Options\Preferences\Junk E-mail\Trust e-mail from contacts

Impact:

When disabled, emails from certain contacts may be classified as junk mail, depending on their content. Outlook users will need to check their junk email folder more frequently to avoid missing important messages. However, this increased scrutiny can lead to a decreased level of trust in these emails.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 25a05a5fc7a0b5e25f32fb2b2345be94a569fd917b7cef9d7e4f0fae966e39c5