Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
Verify the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Disable user name and password” is set to “Enabled” and ‘outlook.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value outlook.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Disable user name and password” to “Enable” and the "outlook.exe" check box is checked. Click "Apply".
Verify the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Bind to Object” is set to “Enabled” and "outlook.exe" check box is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value outlook.exe is REG_DWORD = 1, this is not a finding.
For the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Bind to Object” select “Enabled” and select the "outlook.exe" check box.
Verify the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Saved from URL” is set to “Enabled” and the "outlook.exe" check box is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value outlook.exe is REG_DWORD = 1, this is not a finding.
The policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Saved from URL” will be set to “Enabled” and "outlook.exe" is checked.
Verify the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” is set to “Enabled” and ‘outlook.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value outlook.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” to “Enabled” and select the "outlook.exe" check box.
Verify the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Block popups” is set to “Enabled” and "outlook.exe" check box is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value outlook.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration>> Administrative Templates>>Microsoft Office 2007 system (Machine)>>Security Settings>>IE Security “Block popups” to “Enabled” and select "outlook.exe" check box. Click "Apply".
The intent of this check is to allow content from Safe Zones automatically. In order to allow for content from Safe Zones automatically, the setting for "Do not permit download of content from safe zones" must be set to "Disabled". All other content will be blocked. In addition, the resulting registry key for "UnblockSafeZone" will be true, or a REG_DWORD value of "1", meaning Safe Zone content will be unblocked. Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Do not permit download of content from safe zones” to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value UnblockSafeZone is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Do not permit download of content from safe zones” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Access to published calendars” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal Criteria: If the value RestrictedAccessOnly is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Access to published calendars” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Add e-mail recipients to users' Safe Senders Lists” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value JunkMailTrustOutgoingRecipients is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Add e-mail recipients to users' Safe Senders Lists” will be set to “Disabled”.
The policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security “Allow Active X One Off Forms” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ If the registry value “AllowActiveXOneOffForms” exists, this is a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security “Allow Active X One Off Forms” to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security “Allow scripts in one-off Outlook forms” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value EnableOneOffFormScripts is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security “Allow scripts in one-off Outlook forms” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Automatic Picture Download Settings “Block Trusted Zones” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value TrustedZone is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Automatic Picture Download Settings “Block Trusted Zones” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Configure Add-In Trust Level” will be set to “Enabled (Trust all loaded and installed COM addins)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value AddinTrust is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Configure Add-In Trust Level” will be set to “Enabled (Trust all loaded and installed COM addins)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when accessing address information via UserProperties.Find” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMAddressUserPropertyFind is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when accessing address information via UserProperties.Find” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when accessing an address book” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMAddressBookAccess is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when accessing an address book” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Allow users to demote attachments to Level 2” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value AllowUsersToLowerAttachments is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Allow users to demote attachments to Level 2” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt When accessing the Formula property of a UserProperty object” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMFormulaAccess is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt When accessing the Formula property of a UserProperty object” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when executing Save As” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMSaveAs is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when executing Save As” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when reading address information” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMAddressInformationAccess is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when reading address information” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when responding to meeting and task requests” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMMeetingTaskRequestResponse is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when responding to meeting and task requests” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when sending mail” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMSend is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security “Configure Outlook object model prompt when sending mail” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security -> Trusted Add-ins “Configure trusted add-ins” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\TrustedAddins If the registry key exists, this is a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Programmatic Security -> Trusted Add-ins “Configure trusted add-ins” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail Setup “Dial–up options” will be set to “Enabled” and Hang up when finished sending, receiving, or updating is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value Hangup after Spool is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail Setup “Dial–up options” will be set to “Enabled” and Hang up when finished sending, receiving, or updating is selected.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail Setup “Dial–up options” will be set to “Enabled” and Warn before switching dial-up connection is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail\ Criteria: If the value Warn on Dialup is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail Setup “Dial–up options” will be set to “Enabled” and Warn before switching dial-up connection is selected.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Disable ‘Remember password’ for Internet e-mail accounts” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value EnableRememberPwd is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Disable ‘Remember password’ for Internet e-mail accounts” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Do not prompt about Level 1 attachments when closing an item” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value DontPromptLevel1AttachClose is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Do not prompt about Level 1 attachments when closing an item” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Do not prompt about Level 1 attachments when sending an item” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value DontPromptLevel1AttachSend is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Do not prompt about Level 1 attachments when sending an item” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value DisableContinueEncryption is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> RSS Feeds “Download full text of articles as HTML attachments” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS Criteria: If the value EnableFullTextHTML is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> RSS Feeds “Download full text of articles as HTML attachments” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Trust Center “Enable links in e-mail messages” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value JunkMailEnableLinks is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Trust Center “Enable links in e-mail messages” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Exchange “Enable RPC encryption” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\RPC Criteria: If the value EnableRPCEncryption is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Exchange “Enable RPC encryption” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Hide Junk Mail UI” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook Criteria: If the value DisableAntiSpam is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Hide Junk Mail UI” will be set to “Disabled”.
The intent of this requirement (DTOO274) is to prevent content from the Internet from being automatically downloaded. This requirement (DTOO274) is coupled with DTOO272 which dictates whether content from Safe Zones is automatically downloaded or not. Since DTOO272 allows for content from Safe Zones to be automatically downloaded, this requirement (DTOO274) prevents the Internet from being considered as a Safe Zone. Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Include Internet in Safe Zones for Automatic Picture Download” is set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value Internet is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Include Internet in Safe Zones for Automatic Picture Download” will be set to “Disabled”.
The intent of this requirement (DTOO275) is to prevent content from the Intranet from being automatically downloaded. This requirement (DTOO275) is coupled with DTOO272 which dictates whether content from Safe Zones is automatically downloaded or not. Since DTOO272 allows for content from Safe Zones to be automatically downloaded, this requirement (DTOO275) prevents the Intranet from being considered as a Safe Zone. Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Include Intranet in Safe Zones for Automatic Picture Download” is set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value Intranet is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Include Intranet in Safe Zones for Automatic Picture Download” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Display Level 1 attachments” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value ShowLevel1Attach is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Attachment Security “Display Level 1 attachments” will be set to “Disabled”.
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Display pictures and external content in HTML email” is set to “Enabled”. NOTE: When this setting is Enabled, Outlook 2007 blocks automatic download of content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value BlockExtContent is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Automatic Picture Download Settings “Display pictures and external content in HTML email” to “Enabled”. Click "Apply".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail format “Do not allow creating, replying, or forwarding signatures for e-mail messages” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Common\MailSettings Criteria: If the value DisableSignatures is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail format “Do not allow creating, replying, or forwarding signatures for e-mail messages” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Do not allow folders in non-default stores to be set as folder home pages” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value NonDefaultStoreScript is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Do not allow folders in non-default stores to be set as folder home pages” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Do not allow Outlook object model scripts to run for public folders” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PublicFolderScript is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Do not allow Outlook object model scripts to run for public folders” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Do not allow Outlook object model scripts to run for shared folders” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value SharedFolderScript is REG_DWORD = 0, this is not a finding
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Do not allow Outlook object model scripts to run for shared folders” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not check e-mail address against address of certificates being used” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value SupressNameChecks is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not check e-mail address against address of certificates being used” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Internet Calendars “Do not include Internet Calendar integration in Outlook” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\WebCal Criteria: If the value Disable is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Internet Calendars “Do not include Internet Calendar integration in Outlook” will be set to “Enabled”.
The policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Cryptography >> Signature Status dialog box “Attachment Secure Temporary Folder” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ If the registry value “OutlookSecureTempFolder” exists, this is a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Cryptography >> Signature Status dialog box “Attachment Secure Temporary Folder” to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Exchange “Authentication with Exchange Server” will be set to “Enabled (Kerberos/NTLM Password Authentication)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value AuthenticationService is REG_DWORD = 9, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Exchange “Authentication with Exchange Server” will be set to “Enabled (Kerberos/NTLM Password Authentication)”.
NOTE: If Outlook 2007 is configured to access DoD Enterprise Email, this check is not applicable. The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Exchange “Automatically configure profile based on Active Directory Primary SMTP address” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\AutoDiscover Criteria: If the value ZeroConfigExchange is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Exchange “Automatically configure profile based on Active Directory Primary SMTP address” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Internet Calendars “Automatically download attachments” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\WebCal Criteria: If the value EnableAttachments is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> Internet Calendars “Automatically download attachments” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Automatic Picture Download Settings “Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value UnblockSpecificSenders is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Automatic Picture Download Settings “Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Junk E-mail protection level” will be set to “Enabled (Low)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value JunkMailProtection is REG_DWORD = 6 (hex or decimal), this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Junk E-mail protection level” will be set to “Enabled (Low)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other “Make Outlook the default program for E-mail, Contacts, and Calendar” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\General Criteria: If the value Check Default Client is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other “Make Outlook the default program for E-mail, Contacts, and Calendar” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Message Formats” will be set to “Enabled (S\MIME)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value MsgFormats is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Message Formats” will be set to “Enabled (S\MIME)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography -> Signature Status dialog box "Missing root certificates" will be set to "Enabled (error)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value SigStatusNoTrustDecision is REG_DWORD = 2, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography -> Signature Status dialog box “Missing root certificates” will be set to “Enabled (error)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings “Outlook Security Mode” will be set to “Enabled (Use Outlook Security Group Policy)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value AdminSecurityMode is REG_DWORD = 3, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings “Outlook Security Mode” will be set to “Enabled (Use Outlook Security Group Policy)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail format -> Internet Formatting “Plain text options” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Common\MailSettings\ PlainWrapLen If the Registry key exists, this is a finding. OR The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail format -> Internet Formatting "Plain text -> options" will be set to "Enabled" where line length is "132" and that NO Check is visible in the "Encode all attachments in UUENCODE format when sending a plain text message" checkbox option. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Common\MailSettings\ PlainWrapLen Criteria: If the value PlainWrapLen is REG_DWORD = 132, this is not a finding. AND HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail. Criteria: If the value Message Plain Format MIME is REG_DWORD = 1, this is not a finding. (Note: Any value for HKCU\Software\Policies\Microsoft\Office\12.0\Common\MailSettings\PlainWrapLen is acceptable.) NOTE: This check is compliant as long as it is matched and defined by setting exactly to one of the above methods.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Mail format -> Internet Formatting "Plain text options" will be set to "Disabled" OR will be set to "Enabled, automatically wrap text option will be set to 132, and no check selection will be included in the Encode all attachments in UUENCODE format when sending a plain text message" checkbox option.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Prevent publishing to a DAV server” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal\ Criteria: If the value DisableDav is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Prevent publishing to a DAV server” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Prevent publishing to Office Online” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal Criteria: If the value DisableOfficeOnline is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Prevent publishing to Office Online” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Prevent users from customizing attachment security” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook Criteria: If the value DisallowAttachmentCustomization is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Prevent users from customizing attachment security” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> E-mail Options “Read e-mail as plain text” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value ReadAsPlain is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> E-mail Options “Read e-mail as plain text” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> E-mail Options “Read signed e-mail as plain text” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value ReadSignedAsPlain is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> E-mail Options “Read signed e-mail as plain text” will be set to “Enabled”.
The policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Security Form Settings >> Attachment Security “Remove file extensions blocked as Level 1” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ If the registry value “FileExtensionsRemoveLevel1” exists, this is a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Security Form Settings >> Attachment Security “Remove file extensions blocked as Level 1” to “Disabled”.
The policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Security Form Settings >> Attachment Security “Remove file extensions blocked as Level 2” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ If the registry value “FileExtensionsRemoveLevel2” exists, this is a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Security >> Security Form Settings >> Attachment Security “Remove file extensions blocked as Level 2” to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Restrict level of calendar details users can publish” will be set to “Enabled (Disables ‘Full details’ and ‘Limited details’)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal Criteria: If the value PublishCalendarDetailsPolicy is REG_DWORD = 4000 (hex) or 16384 (Decimal), this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Restrict level of calendar details users can publish” will be set to “Enabled (Disables ‘Full details’ and ‘Limited details’)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Restrict upload method” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal Criteria: If the value SingleUploadOnly is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Restrict upload method” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography -> Signature Status dialog box “Retrieving CRLs (Certificate Revocation Lists)” will be set to “Enabled (When online always retrieve the CRL)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value UseCRLChasing is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography -> Signature Status dialog box “Retrieving CRLs (Certificate Revocation Lists)” will be set to “Enabled (When online always retrieve the CRL)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Run in FIPS compliant mode” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value FIPSMode is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Run in FIPS compliant mode” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME interoperability with external clients” will be set to “Enabled (Handle internally)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value ExternalSMime is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME interoperability with external clients” will be set to “Enabled (Handle internally)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME password settings” will be set to “Enabled” and Default S/MIME password time will be set to 30. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Cryptography\Defaults\Provider\ Microsoft Exchange Cryptographic Provider v1.0 Criteria: If the value DefPwdTime is REG_DWORD = 1e (hex) or 30 (decimal), this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME password settings” will be set to “Enabled” and Default S/MIME password time will be set to 30.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME password settings” will be set to “Enabled” and Maximum S/MIME password time will be set to 300. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Cryptography\Defaults\Provider\ Microsoft Exchange Cryptographic Provider v1.0 Criteria: If the value MaxPwdTime is REG_DWORD = 12c (hex) or 300 (decimal), this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME password settings” will be set to “Enabled” and Maximum S/MIME password time will be set to 300.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME receipt requests” will be set to “Enabled (Never send S\MIME receipts)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value RespondToReceiptRequests is REG_DWORD = 2, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “S/MIME receipt requests” will be set to “Enabled (Never send S\MIME receipts)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Trust Center “Security setting for macros” will be set to “Enabled (Always warn)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value Level is REG_DWORD = 2, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Trust Center “Security setting for macros” will be set to “Enabled (Always warn)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Send all signed messages as clear signed messages” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value ClearSign is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Send all signed messages as clear signed messages” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security “Set control ItemProperty prompt” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMItemPropertyAccess is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security “Set control ItemProperty prompt” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security “Set Outlook object model Custom Actions execution prompt” will be set to “Enabled (Automatically Deny)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value PromptOOMCustomAction is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Security Form Settings -> Custom Form Security “Set Outlook object model Custom Actions execution prompt” will be set to “Enabled (Automatically Deny)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Signature Warning” will be set to “Enabled (Always warn about invalid signatures)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value WarnAboutInvalid is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Signature Warning” will be set to “Enabled (Always warn about invalid signatures)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> RSS Feeds “Synchronize Outlook RSS Feeds with Common Feed List” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS Criteria: If the value SyncToSysCFL is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Account Settings -> RSS Feeds “Synchronize Outlook RSS Feeds with Common Feed List” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Trust E-mail from Contacts” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value JunkMailTrustContacts is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Trust E-mail from Contacts” will be set to “Enabled”.
NOTE: For operational environments requiring the use of RSS feeds integrated into Outlook for mission need, the network environment must meet the following criteria: - both the web site issuing the RSS feeds and the Outlook email client both have an available network path to each other. - neither the web site issuing the RSS feeds nor the Outlook email client have a network path to the public Internet. An example of such an environment would be a closed lab or other deployed network where the requisite signoffs, artifacts, and network documentation demonstrate that the Public Internet is not available to the Outlook client, preventing unauthorized RSS subscriptions being accessed by users of the Outlook client. If an operational environment has RSS Feeds enabled, and the mission need is documented and approved by the ISSO/ISSM, and the network meets the appropriate requirement, this is Not a Finding. For all environments where the Outlook email client has access to public Internet web sites, RSS integration into Outlook is not permitted, and should be validated as follows. Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Tools|Account Settings >> RSS Feeds "Turn off RSS feature" is set to "Enabled". Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS Criteria: If the environment meets the above stated criteria, and value "Disable" is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office Outlook 2007 >> Tools|Account Settings >> RSS Feeds “Turn off RSS feature” to “Enabled”. Click Apply.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Use Unicode format when dragging e-mail message to file” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\General Criteria: If the value MSGFormat is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Other -> Advanced “Use Unicode format when dragging e-mail message to file” will be set to “Disabled”.
To determine what service pack level is installed, start the Office application. Click on the Office Menu Button (upper left), click "Options" at the bottom of the menu, and select "Resources" from the left column. The version number will be displayed alongside the "About" button on the right-hand side display. If the "About" box information displays an Office 2007 version, this is a finding.
Upgrade to Office 2010, Office 2013, or Office 2016.
The intent of this check is to block the display of Internet and network paths as hyperlinks in email messages. This requirement cannot be configured in the Office 2007 Administrative Templates. It can either be configured individually, within each Outlook client, or by registry key. To verify within the Outlook client that "Internet and network path into hyperlinks" is not enabled: From the main Outlook window, go to Tools >> Options. Select the "Mail Format" tab. Select the "Editor Options" button. In the left pane, select the "Proofing" button. Select the "AutoCorrect" button. Select the "AutoFormat As You Type" tab. Criteria: If the "Internet and network path into hyperlinks" checkbox is selected, this is a finding. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\software\policies\Microsoft\office\12.0\outlook\options\autoformat Criteria: If the value pgrfafo_25_1 is REG_DWORD = 1, this is a finding.
Use the Windows Registry Editor to navigate to the following key: HKCU\software\policies\Microsoft\office\12.0\outlook\options\autoformat If the REG_DWORD value for pgrfafo_25_1 does not exist, create it with a value of "0". If the REG_DWORD value for pgrfafo_25_1 does exist, change the value to "0".