2.5.14.4.2 Ensure 'Apply macro security settings to macros, add-ins and additional actions' is set to 'Enabled'

Information

This policy setting controls whether Outlook also applies the macro security settings to installed COM add-ins and additional actions.

The recommended state for this setting is: Enabled.

Rationale:

Attackers can insert malicious code into add-ins and smart tags in an attempt to affect your computing environment. By default, COM add-ins and smart tags are not subject to the same security restrictions as installed macros.

Impact:

Add-ins and smart tags will run under greater security restrictions. This configuration might have an impact on users that use add-ins and smart tags.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Trust Center\Apply macro security settings to macros, add-ins and additional actions

Default Value:

Disabled. (Outlook does not use the macro security settings to determine whether to run macros, installed COM add-ins, and additional actions.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3a.

Plugin: Windows

Control ID: 1d196a5dc27b5d9b9c315d3ecdb7257c75582fe4839d48b00dcb9e5a48c5fbd9