Group policy object BSI guidelines for the secure configuration of Microsoft Outlook 2016

Ano Nymus 1 Reputation point
2021-06-01T06:49:30.653+00:00

Hello everybody :)

We want to implement the BSI guidelines for the secure configuration of Microsoft Outlook 2016.
Here, however, we encounter the problem described below:

In accordance with the above guidelines, the following group policy user settings at the branch

'Microsoft Outlook 2016/Security/Security Form Settings/Programmatic Security/' are set to "Automatically reject":

  • Configure Outlook object model prompt when responding to meeting and task requests
  • Configure Outlook object model prompt when accessing an address book
  • Configure Outlook object model prompt when reading address information
  • Configure Outlook object model prompt When accessing the Formula property of a UserProperty object
  • Configure Outlook object model prompt when executing Save As
  • Configure Outlook object model prompt when sending mail

However, since we use third-party software that automatically sends e-mails and uses Outlook and the Exchange address book, we configured the relevant DLL with an MD5 hash value to the group policy user settings at the branch

'Microsoft Outlook 2016/Security/Security Form Settings/Programmatic Security/Trusted Add-Ins/'.

Nevertheless, automated e-mails can no longer be sent from the third-party software.
What is wrong with this setting?

sincerly

Anonymus

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,719 questions
Outlook Management
Outlook Management
Outlook: A family of Microsoft email and calendar products.Management: The act or process of organizing, handling, directing or controlling something.
4,868 questions
Office Management
Office Management
Office: A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.Management: The act or process of organizing, handling, directing or controlling something.
1,996 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. ChristyZhang-MSFT 20,706 Reputation points Microsoft Vendor
    2021-06-02T04:18:18.977+00:00

    Hi @Ano Nymus ,

    According to my research and search, I found an official document that describes how to manage trusted add ins in detail: Manage trusted add-ins for Outlook 2010, please refer to this article to see if it is different from your configuration.

    Meanwhile, I found in the discussion of some posts that if you want to successfully start the security policy, you need to enforce outlook security settings. If you do not configure these related settings, it is suggested that you could refer to the settings of outlook security mode for configuration to check whether there are differences.

    Considering that I don't know which method you use to get the hash value and the configuration of DLL, and we are unable to test the same three-party software, if possible, it is suggested that you could change the way to get the hash value and configure other trusted add in to check whether there is any difference.

    Hope the above is helpful to you. Please contact us if you have any questions!


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Ano Nymus 1 Reputation point
    2021-06-02T06:55:54.147+00:00

    Good morning dear ChristyZhang-MSFT :)

    Many thanks you for your effort and your reply. We use Group policy objects in an Active Directory environment SchemaVersion 87 with Exchange Schema Version 15333. This Outlook GPO is assigned to an organizational unit within the Active Directory. The GPO is active and enforced and is distritbuted to all objects within the mentioned OU.

    I checked twice your mentioned Microsoft document, but did not found any difference to my configuration.
    The hash of the DLL can get with the Powershell utility "Get-FileHash":

    • Get-FileHash
      [-Path] <String[]>
      [[-Algorithm] <String>]
      [<CommonParameters>]

    I used the SHA256 and the MD5 Hash of the DLL as well to check if there is any difference but it doesn't seem so.
    But meanwhile I configured the following settings to "Prompt users based on their computer security"

    • Configure Outlook object model prompt when accessing an address book
    • Configure Outlook object model prompt when reading address information
    • Configure Outlook object model prompt when sending mail

    ...and it seems to work now.

    But I'm still unsure if this is the appropriate setting for this configuration or if I just lowered down the security level.

    I guess I need some more research to find a resilient answer.

    But again, many thanks for your help!

    Sincerly
    Anonymus


  3. Ano Nymus 1 Reputation point
    2021-06-07T06:59:25.747+00:00

    Hello dear @ChristyZhang-MSFT

    Many thanks for your reply!

    I forwarded your thoughts and the mentioned articles to our developers. They will research and tell me, if our add-ins is compliant to the trust and security level.
    I guess that our add-ins fulfill the requirements, but it's always better to look precisely. ;)

    I'll come back when i have more to say about it. Meanwhile, many thanks for your help!

    Sincerly
    Anonymus