Details
This policy setting prevents users from overriding the set of attachments blocked by
Outlook. If you enable this policy setting users will be prevented from overriding the set of
attachments blocked by Outlook. Outlook also checks the ‘Level1Remove’ registry key
when this setting is specified. If you disable or do not configure this policy setting, users
will be allowed to override the set of attachments blocked by Outlook. The recommended
state for this setting is- Enabled.
*Rationale*
If users are able to change the security settings for attachments they could choose less
secure values and increase the risk of unintentionally spreading malware.
Solution
To implement the recommended configuration state, set the following Group Policy setting
to Enabled.
User ConfigurationAdministrative TemplatesMicrosoft Outlook 2010SecurityPrevent
users from customizing attachment security settings
Impact-Enabling this setting cause some users to be frustrated that they cannot customize the
attachment security settings, but in most environments this should not be a significant
issue.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: System and Information Integrity.This control applies to the following type of system Windows.