2.5.10.11 Ensure 'Internet and network paths into hyperlinks' is set to 'Disabled'

Information

This policy setting specifies whether Outlook automatically turns text that represents Internet and network paths into hyperlinks. This option can also be configured by selecting the 'Internet and network paths with hyperlinks' check box that is available on the Outlook.

The recommended state for this setting is: Disabled.

Rationale:

Users may receive emails from attackers that contain Internet or network paths to malicious content. Users may unintentionally click on hyperlinks if they are presented to the users automatically.

Impact:

Users will not be able to click on hyperlinks for Internet and network paths. Instead they will need to manually copy and paste the URL or path.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Internet and Network Paths into Hyperlinks

Default Value:

Enabled. (Applicable text is automatically turned into hyperlinks.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: dac2775219b7bb2289c9e12d74a2f9ddf6ff06f0463eaa5381217b22b96f8f59