2.5.10.6.3 Ensure 'Make Outlook the default program for E-mail, Contacts, and Calendar' is set to 'Enabled'

Information

This policy setting controls whether Outlook is the default program for e-mail, contacts, and calendar services. If this policy setting is enabled, the 'Make Outlook the default program for E-mail, Contacts, and Calendar' check box on the General tab of the Office Center is selected and users cannot change it.

The recommended state for this setting is: Enabled.

Rationale:

If another application is used to provide these services and your organization does not ensure the security of that application, it could be exploited to gain access to sensitive information or launch other malicious attacks. If the organization has policies that govern the use of personal information management software, allowing users to change the default configuration could enable them to violate such policies.

Impact:

In most environments that use the Microsoft Office system, Outlook is often already the default program for e-mail, contacts, and calendaring for most users. Enabling this setting is therefore unlikely to cause usability issues.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Other\Make Outlook the default program for E-mail, Contacts, and Calendar

Default Value:

Enabled. (Outlook is the default, but users can change the setting.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|SC-18

Plugin: Windows

Control ID: 979b87cb60fb0268b57016a7f5c5fc2c8ee7d8dc72367bc0c8e2f0938ebdb384