1.9.11 Ensure 'Internet and Network Paths into Hyperlinks' is set to Disabled

Information

This policy setting specifies whether Outlook automatically turns text that represents Internet and network paths into hyperlinks. This option can also be configured by selecting the 'Internet and network paths with hyperlinks' check box that is available on the Outlook | File | Options | Mail | Editor Options.... | Proofing | AutoCorrect Options | AutoFormat tab on the user interface (UI).

If you enable or do not configure this policy setting, text in Outlook that represents internet and network paths are automatically turned into hyperlinks. This is the default behavior of Outlook.

If you disable this policy setting, text in Outlook that represents internet and network paths are not automatically turned into hyperlinks. The recommended state for this setting is: Disabled.

Rationale:

Users may receive emails from attackers that contain Internet or network paths to malicious content. Users may unintentionally click on hyperlinks if they are presented to the users automatically.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Disabled.

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Internet and Network Paths into Hyperlinks

Impact:

Users will not be able to click on hyperlinks for Internet and network paths. Instead they will need to manually copy and paste the paths (if desired).

See Also

https://workbench.cisecurity.org/files/553

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 12008f23ac2cb05797ebb0a2c293783063458007c88162a2b7a5371c26c61c32