21.2 (L1) Ensure 'Allow Email Scanning' is set to 'Allowed'

Information

This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac).

The recommended state for this setting is: Allowed

Incoming e-mails should be scanned by an antivirus solution such as Microsoft Defender Antivirus, as email attachments are a commonly used attack vector to infiltrate computers with malicious software.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Allowed

Defender\Allow Email Scanning

Impact:

E-mail scanning by Microsoft Defender Antivirus will be enabled.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 123f4244c671a40b6d3d29831d628edfac92c28a26cc6b96814b2492a57b822b