Home > Ask the Microsoft Exchange Experts > Richard Luckett: Spam and Security Questions & Answers > Prevent users from opening encrypted messages
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Prevent users from opening encrypted messages

Richard Luckett EXPERT RESPONSE FROM: Richard Luckett

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 01 July 2005
We have found and enabled the Outlook 2003 group policy objects that prevent our users from sending signed and/or encrypted messages. How do we prevent our users from opening encrypted messages?

>
EXPERT RESPONSE
I'm most curious as to the reason you do not want encrypted or at least digitally signed e-mail. But we can save that for another time.

As you stated, the group policy objects for Outlook allows you to control the creation but not the viewing. If you are intent on not allow any S/MIME certificates, which are used for encrypting and digitally signing e-mail, you can actually configure your information stores in Exchange so they will not be able store S/MIME; this will also prevent the delivery of signed and encrypted items.

  1. Using the Exchange System Manager, navigate to the mailbox store that has your user mail on it.
  2. Now go to the properties page for the mailbox store.
  3. On the General tab, de-select the checkbox "Clients support S/MIME signatures."

This option was designed to allow compatibility for legacy clients but will have the affect that you are after. On the downside a non-delivery report will be returned to the originator of the encrypted or digitally signed message.

In my humble opinion, though, this is not to be done for security reasons. If you are doing this because your antivirus software doesn't support scanning encrypted e-mail, you should look for one that does, or simply look for one that uses the latest VSAPI (2.5 with Exchange 2003) where S/MIME scanning is supported natively.


Do you have comments on this Ask the Expert Q&A? Let us know.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Microsoft Outlook
Does Exchange cached mode work with all versions of Microsoft Outlook?
How to access SharePoint sites through Microsoft Outlook
What makes Microsoft Outlook 2007's Search feature special?
Uncovering Microsoft Outlook 2007's hidden diagnostic tools
How Microsoft Office Communicator enhances Outlook 2007 functionality
Microsoft Outlook .PST file FAQs
Tool exports messages from Microsoft Outlook to Unix .EML file format
DetachPipe: Outlook add-in tool saves and restores email attachments
Install the Outlook Connector to use Hotmail in Microsoft Outlook
A few favorite Microsoft Exchange Server blogs
Microsoft Outlook Research

Richard Luckett: Spam and Security
Selectively set email permissions for Exchange groups
What event log tracks user access to Exchange Server?
Public folder permissions fail in Exchange mixed mode
Locate 'missing' SPF record on an external DNS domain
Enhance OWA logon security using Microsoft ISA Server
Native Exchange Server 2003 antispam solutions
Configure IMF's Gateway SCL to improve spam filtering
POP3 server filters all email into Junk folder as spam
Setting up an SSL certificate for OWA without a public IP address
Creating one password for both local and Microsoft Outlook user accounts

Email Encryption
Deploying ISA Server as a firewall for Exchange Server mobile devices
How to set up an SSL certificate to encrypt OWA and ActiveSync traffic
A Microsoft Outlook email security tutorial -- 8 tips in 8 minutes
Zip and encrypt Microsoft Outlook email attachments
Microsoft Outlook email encryption simplified
Microsoft repackages e-mail hosting service
Time lag opening and sending encrypted e-mails
Best encryption method for an Outlook .PST file
How to (really) address HIPAA
WinZip releases encryption tool for Outlook

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bacn  (SearchExchange.com)
email bankruptcy  (SearchExchange.com)
offline folder file  (SearchExchange.com)
OST file  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts