Information
This policy setting controls how Outlook warns users about messages with invalid digital signatures.
The recommended state for this setting is: Enabled: Always warn about invalid signatures.
Rationale:
If users are not notified about invalid signatures, it might prevent the user from detecting a fraudulent signature sent by a malicious user.
Impact:
None - This is the default behavior.
Enabling this setting could cause some disruptions for Outlook users who receive a lot of e-mail messages signed with invalid signatures. These users will see a warning dialog box every time they open a signed e-mail message.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Always warn about invalid signatures:
User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\Signature Warning
Default Value:
Disabled. (Users open e-mail messages that include invalid digital signatures, Outlook displays a warning dialog. Users can decide whether they want to be warned about invalid signatures in the future. )