UCF STIG Viewer Logo

Trust EMail from senders in receivers contact list must be enforced.


Overview

Finding ID Version Rule ID IA Controls Severity
V-17807 DTOO223 SV-53882r1_rule Medium
Description
Email addresses in users' Contacts list are treated as safe senders for purposes of filtering junk email. If this configuration is changed, email from users' Contacts might be misclassified as junk and cause important information to be lost.
STIG Date
Microsoft Outlook 2013 STIG 2018-09-05

Details

Check Text ( C-47916r1_chk )
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Outlook Options -> Preferences -> Junk E-mail "Trust E-mail from Contacts" is set to "Enabled".

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\15.0\outlook\options\mail

Criteria: If the value JunkMailTrustContacts is REG_DWORD = 1, this is not a finding.
Fix Text (F-46788r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Outlook Options -> Preferences -> Junk E-mail "Trust E-mail from Contacts" to "Enabled".