Policy
Required Certificate Authority
Microsoft Office 5532.1000
Policy overview
Key metadata and intent for this policy.
This policy setting enables you to designate a required certificate authority for Outlook to use for encryption and digital signatures. If you enable this policy setting, you can specify a required certificate authority by entering an X.509 distinguished name in the text field that is provided. The name must conform to the X.509 certificate format exactly. For example: CN=WoodgroveBankCA, DC=WoodgroveBank, DC=com If you disable or do not configure this policy setting, Outlook trusts any certificate authorities that are represented by certificates in the Trusted Root Certification Authorities store on users' computers.
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
X.509 issue DN that restricts choice of certifying authorities: ID L_X509issueDNthatrestrictschoiceofcertifyingauthorities | text | HKCU\software\policies\microsoft\office\16.0\outlook\security\requiredca Type REG_SZ | None |
Other policies in this category
Explore related policies at the same level.
- UserAlways use TNEF formatting in S/MIME messagesWindows7
- UserCheck for the user's private key when the user sends an encrypted email that includes the user as a recipientWindows7
- UserDo not check e-mail address against address of certificates being usedWindows7
- UserDo not display 'Publish to GAL' buttonWindows7
- UserDo not provide Continue option on Encryption warning dialog boxesWindows7
- UserEnable Cryptography IconsWindows7
- UserEnable Retrieval of Remote Certificate Authority InformationWindows7
- UserEncrypt all e-mail messagesWindows7
- UserEnsure all S/MIME signed messages have a labelWindows7
- UserFortezza certificate policiesWindows7
- UserMessage FormatsWindows7
- UserMessage when Outlook cannot find the digital ID to decode a messageWindows7