2.5.14.2.7 Ensure 'Signature Warning' is set to 'Enabled: Always warn about invalid signatures'

Information

This policy setting controls how Outlook warns users about messages with invalid digital signatures.

The recommended state for this setting is: Enabled: Always warn about invalid signatures.

Rationale:

If users are not notified about invalid signatures, it might prevent the user from detecting a fraudulent signature sent by a malicious user.

Impact:

None - This is the default behavior.

Enabling this setting could cause some disruptions for Outlook users who receive a lot of e-mail messages signed with invalid signatures. These users will see a warning dialog box every time they open a signed e-mail message.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Always warn about invalid signatures:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\Signature Warning

Default Value:

Disabled. (Users open e-mail messages that include invalid digital signatures, Outlook displays a warning dialog. Users can decide whether they want to be warned about invalid signatures in the future. )

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Windows

Control ID: b6068cce89df8a24d44133210b49d09c0115fd69841460550f5888c4d94ffcce