2.5.10.8.4.4 Ensure 'Trust e-mail from contacts' is set to 'Disabled'

Information

This policy setting controls whether Outlook analyzes e-mail from users' Contacts when filtering junk e-mail.

The recommended state for this setting is: Disabled.

Rationale:

E-mail addresses in users' Contacts list are treated as safe senders for purposes of filtering junk e-mail. If a trusted contact's e-mail is hijacked or compromised, the recipient of a spam campaign may become a victim as the e-mail won't receive the same scrutiny from Outlook's junk e-mail filtering.

Impact:

When disabled, users may find the e-mail from a contact could end up in the junk e-mail box depending on the contents of the e-mail. Outlook users will need to check this folder more often as to not miss something, but this will allow for more scrutiny and less trust of said e-mails.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Preferences\Junk E-mail\Trust e-mail from contacts

Default Value:

Enabled. (Contacts are treated as safe senders.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: bba7fd16a334025cade86a1795c4605ffcf84eea8d6733c33c17eec0e3086bac