2.5.1.5.1 Ensure 'Automatically download attachments' is set to 'Disabled'

Information

This policy setting controls whether Outlook downloads files attached to Internet Calendar appointments.

The recommended state for this setting is: Disabled.

Rationale:

Files attached to Internet Calendar appointments could contain malicious code that could be used to compromise a computer. By default, Outlook does not download attachments when retrieving Internet Calendar appointments.

Impact:

Disabling this setting enforces the default configuration in Outlook, and therefore is unlikely to cause usability issues for most users.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Account Settings\Internet Calendars\Automatically download attachments

Default Value:

Disabled.

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-8

Plugin: Windows

Control ID: 71df2a380255f76c87d6e2a0677e3c9b73564c61729774413e5148eb81127a2a