2.5.14.3.24 (L1) Ensure 'Prevent users from customizing attachment security settings' is set to 'Enabled'

Information

This policy setting prevents users from overriding the set of attachments blocked by Outlook.

Note: Outlook also checks the

Level1Remove

registry key (which could allow the user to save the file to disk) when this setting is specified.

The recommended state for this setting is: Enabled

If users can change the security settings for attachments, they could choose a less secure value and increase the risk of being infected and spreading malware.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Prevent users from customizing attachment security settings

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

Users will not be able to customize the attachment security settings and legitimate attachments might be blocked.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-8

Plugin: Windows

Control ID: 1ca6e8f50473184ce2a22aa939facb12c7bdae068c1f6f26e6a2e4a80eb6a699