2.5.14.8 Ensure 'Prevent users from customizing attachment security settings' is set to 'Enabled'

Information

This policy setting prevents users from overriding the set of attachments blocked by Outlook.

Note: Outlook also checks the Level1Remove registry key (which could allow the user to save the file to disk) when this setting is specified.

The recommended state for this setting is: Enabled.

Rationale:

If users are able to change the security settings for attachments, they could choose a less secure value and increase the risk of being infected and spreading malware.

Impact:

Users will not be able to customize the attachment security settings and legitimate attachments might be blocked.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Prevent users from customizing attachment security settings

Default Value:

Disabled. (Users will be allowed to override the set of attachments blocked by Outlook.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-8

Plugin: Windows

Control ID: 860d2300d7e26801c91f375b4237162626481dab86761d37297baca9b6f656dd