2.5.14.3.20 (L1) Ensure 'Include Internet in Safe Zones for Automatic Picture Download' is set to 'Disabled'

Information

This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so.

When Disabled, Outlook does not consider the Internet a safe zone, which means that Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.

The recommended state for this setting is: Disabled

E-mails sourced from the internet can contain malicious content or phishing links. This security control prevents the content in e-mail messages from automatically reaching the end user, as well as preventing the changing of this setting to an insecure state.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Include Internet in Safe Zones for Automatic Picture Download

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: 4239ca921afe4cdd8472fca2bbe50fe947cd44d3fd3923d533f7197f5dc40dd2