2.5.14.2.2 Ensure 'Do not display 'Publish to GAL' button' is set to 'Enabled'

Information

This policy setting controls whether Outlook users can publish e-mail certificates to the Global Address List (GAL). The GAL contains information for all email users, distribution groups, and Exchange resources.

The recommended state for this setting is: Enabled.

Rationale:

Only Administrators should be able to perform tasks such as publishing digital certificates to the GAL.

Impact:

Only Administrators will be able to publish a new or updated certificate to the GAL.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\Do not display 'Publish to GAL' button

Default Value:

Disabled. (Outlook users can publish their e-mail certificates to the GAL through the 'E-mail Security' section of the Trust Center.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 6f51597e10314f0362a31105d1e812581ec8656ac54da6cd9fcdc2bce5328535