Information
This policy setting specifies whether replies will be automatically (digitally) signed.
The recommended state for this setting is: Disabled.
Rationale:
Disabling this setting and allowing automatic digital signatures will ensure the original sender of a signed message also receives a signed one in return. Breaking the integrity in this trust relationship may cause the other party to disregard the sender's message, causing information and trust to be lost.
Impact:
None - this is the default behavior.
Solution
To establish the recommended configuration via GP, set the following UI path to Disabled:
User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Do not automatically sign replies
Default Value:
Disabled. (A signed response will be the default reply to a signed message.)