2.3.5 Ensure 'Enable S/MIME for OWA' is set to 'True'

Information

This policy setting is used to control whether users are allowed to download the Secure/Multipurpose Internet Mail Extensions (S/MIME) control to read and create signed and encrypted messages.

Rationale:

S/MIME uses digital signatures and encryption to protect against several classes of attacks including eavesdropping, impersonation, and tampering.

Impact:

Users will be able to use the S/MIME control when accessing their e-mail via OWA.

This is the default value.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-OWAVirtualDirectory 'owa (Default Web Site)' -SMimeEnabled $true

Default Value:

True

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: e9e50566f6cc287831fa8049e44e589e63723fe7758d19f8731302689b170c72