2.5.14.1.4 Ensure 'Do not permit download of content from safe zones' is set to 'Disabled'

Information

This policy setting controls whether Outlook automatically downloads content from safe zones when displaying messages.

Note: This policy setting is backwards. Despite the name, disabling this policy setting prevents the download of content from safe zones and enabling the policy setting allows it.

The recommended state for this setting is: Disabled.

Rationale:

By default, Outlook automatically downloads content from sites that are considered 'safe,' as defined in the Security tab of the Internet Options dialog box in Internet Explorer. This configuration could allow users to inadvertently download Web beacons that reveal their identity to spammers and other malicious people.

Impact:

Users with e-mail messages that include content from safe zones will be required to download content for each message individually.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Automatic Picture Download Settings\Do not permit download of content from safe zones

Default Value:

Enabled. (Outlook automatically downloads content from sites that are considered 'safe,' as defined in the Security tab of the Internet Options dialog box in Internet Explorer.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: dfb01b1ac3a57b341a5dd11e2d3cb4172bb5ae8ba8440ce562c74c728c0e7f0e