2.5.1.2.2 Ensure 'Do not allow users to change permissions on folders' is set to 'Enabled'

Information

This policy setting prevents users from changing their mail folder permissions.

If this policy setting is enabled, Outlook users cannot change permissions on folders; the settings on the Permissions tab are disabled. Enabling this policy setting does not affect existing permissions, and users can still change permissions by sending a sharing message.

The recommended state for this setting is: Enabled.

Rationale:

By default, Outlook users can change the permissions for folders under their control by using the Permissions tab of the Properties dialog box for the folder, or by sending a sharing message. If users change the permissions on a folder they control, it might cause sensitive information in items stored in the folder to be compromised by exposing it to unauthorized people.

Impact:

Enabling this setting prevents Outlook users from sharing folders they control with other users. Users who want to share folders will need to ask an administrator to make the necessary change.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Account Settings\Exchange\Do not allow users to change permissions on folders

Default Value:

Disabled.

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2

Plugin: Windows

Control ID: 1414c5390516ab4353dfdd6be7904d486cf363e438b94584dd20105b10ab9d1e