2.5.14.1.5 Ensure 'Include Internet in Safe Zones for Automatic Picture Download' is set to 'Disabled'

Information

This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so.

When Disabled, Outlook does not consider the Internet a safe zone, which means that Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.

The recommended state for this setting is: Disabled.

Rationale:

E-mails sourced from the internet can contain malicious content or phishing links. This security control prevents the content in e-mail messages from automatically reaching the end user, as well as preventing the changing of this setting to an insecure state.

Impact:

None - this is the default behavor.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Automatic Picture Download Settings\Include Internet in Safe Zones for Automatic Picture Download

Default Value:

Disabled. (Outlook does not consider the internet a safe zone.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: 47311dd4941ee8da297ecca17564da3270e900502c156cd5cbc0ec5a183afbc0