2.5.14.3.4 Ensure 'Outlook Security Mode' is set to 'Enabled: Use Outlook Security Group Policy'

Information

This policy setting controls which set of security settings are enforced in Outlook.

When the option Use Outlook Security Group Policy is selected, Outlook uses security settings from Group Policy.

Note: This setting must be enabled if other Outlook security policy settings mentioned in this guide are applied.

Note #2: In previous versions of Outlook, when security settings were published in a form in Exchange Server public folders, users who needed these settings required the HKEY_CURRENT_USER\Software\Policies\Microsoft\Security:CheckAdminSettings registry key to be set on their computers for the settings to apply. In Outlook, the CheckAdminSettings registry key is no longer used to determine user's security settings. Instead, the Outlook Security Mode setting can be used to determine whether Outlook security should be controlled directly by Group Policy, by the security form from the Outlook Security Settings Public Folder, or by the settings on user's own computers.

The recommended state for this setting is: Enabled: Use Outlook Security Group Policy.

Rationale:

Users should not be able to configure security themselves. Choosing the lowest levels of security can lead to systems being vulnerable to attack.

Note: This setting is essential for ensuring that the other Outlook security settings mentioned in this baseline are applied as suggested.

Impact:

Enabling this setting prevents users from modifying their own security settings, so it might cause an increase in support calls.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Use Outlook Security Group Policy:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode

Default Value:

Disabled. (Outlook users can configure security for themselves, and Outlook ignores any security-related settings that are configured in Group Policy.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 8b9e2d0d620f246be45d5d1ec6d5cd039f196b4f41585416df9420c5dc8b9951