2.5.14.2.1.1 (L1) Ensure 'Attachment Secure Temporary Folder' is set to 'Disabled'

Information

This policy setting allows administrators to specify a folder path for the Secure Temporary Files rather than using the one that is randomly generated by Outlook.

The recommended state for this setting is: Disabled

Setting a designated specific path and folder to use as the Secure Temporary Files folder is not recommended because all users will have temporary Outlook files in the same predictable location, which is not as secure. If the name of this folder is well known, a malicious user or malicious code might target this location to try and gain access to attachments.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Outlook 2016\Security\Cryptography\Signature Status dialog box\Attachment Secure Temporary Folder

Impact:

None - This enforces the default.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 6079622517687d009a169115f64abc25c2506a6990ffd19781e64db766b9b746