1.9.8.4.4 Ensure 'Trust e-mail from contacts' is set to Enabled

Information

This policy setting controls whether Outlook analyzes e-mail from users' Contacts when filtering junk e-mail.
If you enable this policy setting, the 'Also trust E-mail from my Contacts' check box is selected in the Safe Senders tab of the Junk E-mail Options dialog and users cannot change it. E-mail addresses in users' Contacts list are treated as safe senders for purposes of filtering junk e-mail.
If you disable this policy setting, e-mail addresses in users' Contacts list are not treated as safe senders for purposes of filtering junk email, and users cannot change this configuration.
If you do not configure this policy setting, e-mail messages that are received from people who are listed in Contacts are considered safe by the Junk E-mail Filter, but users can change this configuration. The recommended state for this setting is: Enabled.

Rationale:

By default, e-mail addresses in users' Contacts list are treated as safe senders for purposes of filtering junk e-mail. If this configuration is changed, e-mail from users' Contacts might be misclassified as junk and cause important information to be lost.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled.

User Configuration\Administrative Templates\Microsoft Outlook 2013\Outlook Options\Preferences\Junk E-mail\Trust e-mail from contacts

Impact:

Enabling this setting enforces the default configuration in Outlook, and is therefore unlikely to cause any significant usability issues for most users.

See Also

https://workbench.cisecurity.org/files/552

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 73daa250d4f64f959c59b19f96eb96e5a0bf0ed27582814e9c460dc275052948