1.9.8.3.4 Ensure 'Read signed e-mail as plain text' is set to Enabled

Information

This policy setting determines whether Outlook renders all digitally signed e-mail in plain text format for reading. Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML.
If you enable this policy setting, the 'Read all standard mail in plain text' check box option is selected in the 'E-mail Security' section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format.
If you disable or do not configure this policy setting, Outlook displays digitally signed e-mail messages in the format they were received in. The recommended state for this setting is: Enabled.

Rationale:

Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. By default, Outlook displays digitally signed e-mail messages in the format they were received in.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled.

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Preferences\E-mail Options\Read signed e-mail as plain text

Impact:

Enabling this setting forces Outlook to display signed messages in plain text, which could cause disruptions for users who receive signed messages in HTML or RTF formats. Inline graphics in the messages will not display, and the text of formatted messages might become distorted or illegible.

See Also

https://workbench.cisecurity.org/files/553

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 2ef396300e9a5ef4f9b51f985858388f92aa612a08ea480c1d7f110e94aa548c