1.67 O365-LY-000001

Information

The SIP security mode in Lync must be enabled.

GROUP ID: V-223344
RULE ID: SV-223344r1043178

When Lync connects to the server, it supports various authentication mechanisms. This policy allows the user to specify whether Digest and Basic authentication are supported. Disabled (default): NTLM/Kerberos/TLS-DSK/Digest/Basic Enabled: Authentication mechanisms: NTLM/Kerberos/TLS-DSK Gal Download: Requires HTTPS if user is not logged in as an internal user.

Solution

Set the policy value for

Computer Configuration >> Administrative Templates >> Skype for Business 2016 >> Microsoft Lync Feature Policies 'Configure SIP security mode'

to 'Enabled'.

See Also

https://workbench.cisecurity.org/benchmarks/26066