Information
This policy setting controls whether Outlook decodes encrypted messages itself or passes them to an external program for processing.
If the option Handle internally is selected, Outlook decrypts all S/MIME messages itself.
The recommended state for this setting is: Enabled: Handle internally
Rationale:
This setting could allow unauthorized and potentially dangerous programs to handle encrypted messages outside of the organization, which could compromise security.
Impact:
The recommended configuration for this setting is Handle internally, which enforces the default configuration in Outlook and is unlikely to cause usability issues for most users.
In some situations, administrators might wish to use an external program, such as an add-in, to handle S/MIME message decryption. If a designated external program needed to handle S/MIME messages, an exception to this recommendation must be made.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Handle internally:
User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\S/MIME interoperability with external clients
Default Value:
Enabled (Handle if possible.)