2.5.14.2.1.1 Ensure 'Attachment Secure Temporary Folder' is set to 'Disabled'

Information

This policy setting allows administrators to specify a folder path for the Secure Temporary Files rather than using the one that is randomly generated by Outlook.

The recommended state for this setting is: Disabled.

Rationale:

Setting a designated specific path and folder to use as the Secure Temporary Files folder is not recommended because all users will have temporary Outlook files in the same predictable location, which is not as secure. If the name of this folder is well known, a malicious user or malicious code might target this location to try and gain access to attachments.

Impact:

None - This enforces the default.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\Signature Status dialog box\Attachment Secure Temporary Folder

Default Value:

Disabled. (Outlook will assign the Secure Temporary Files folder a different random name for each user.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: a934a27c7211f3cbb85de590f592733d601fc08ccaef0110cef5835c93e6ae16