O365-OU-000027 - Outlook must be configured to not allow hyperlinks in suspected phishing messages.

Information

This policy setting controls whether hyperlinks in suspected phishing e-mail messages in Outlook are allowed. If you enable this policy setting, Outlook will allow hyperlinks in suspected phishing messages that are not also classified as junk e-mail. If you disable or do not configure this policy setting, Outlook will not allow hyperlinks in suspected phishing messages, even if they are not classified as junk e-mail.

Solution

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Outlook 2016 >> Security >> Trust Center 'Allow hyperlinks in suspected phishing e-mail messages' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Office_365_ProPlus_V3R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-223372r961863_rule, STIG-ID|O365-OU-000027, STIG-Legacy|SV-108923, STIG-Legacy|V-99819, Vuln-ID|V-223372

Plugin: Windows

Control ID: 208ab15b6e98cc85f4745300a2db9a6d8315e490b4d72d6d31903b27c949fb2b