トップ回答者
Outlookにてフォルダプロパティのホームページタブが表示されない

質問
回答
-
下記の文書を参考に Registry の 編集を実行してみてください。
Folder Home Pages Aren't Available
https://www.slipstick.com/problems/folder-home-pages-arent-available/
- 回答の候補に設定 栗下 望Microsoft employee, Moderator 2017年10月12日 3:50
- 回答としてマーク takuya_1024 2017年10月16日 4:43
-
FYI
Folder Homepage Settings deprecation
In the October update 10/10/2017 the Folder Homepages setting was deprecated in order to close a security vulnerability.
What was the problem?
When an Exchange mailbox is compromised, e.g. by password spraying, an external attacker can use the Folder Homepage to gain remote code execution within the corporate network by setting the folder homepage to a malicious URL.
The folder homepage roams between clients, which means that an external attacker can set a folder homepage to an arbitrary URL, and then roam that into the Outlook client running within the corporate network.
External publication and exploit tool can be found here https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/
What has changed:
We have disabled reading the folder homepage properties from the folder by default. Since the changing those properties would potentially break other machines that opted-out of this protection, we also disable/hide the property page which would have let the user try to set those properties on the folder.
Work-Around:
If a folder homepage still needs to be set, there are individual registry keys we'll fall back to for each of our special folders and for Outlook Today. The WebView registry keys are specific to default folders. The workaround doesn’t work for folders that the user created and wants to use with a folder homepage.
This does not violate security, since these regkeys do not roam.
There's a registry key customers can set to re-enable roaming folder homepages.
Full documentation of workarounds can be found here (Issue #1) https://support.office.com/en-us/article/Fixes-or-workarounds-for-recent-issues-in-Outlook-for-Windows-ecf61305-f84f-4e13-bb73-95a214ac1230
Those regkeys are:
To turn off folder homepage roaming protection: [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Security] "EnableRoamingFolderHomepages"=dword:00000001
To set a folder home page without disabling protection (replacing Inbox with the folder name): [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\WebView\Inbox] "URL"=http://internalsite/
- 回答の候補に設定 栗下 望Microsoft employee, Moderator 2017年10月16日 0:33
- 回答としてマーク takuya_1024 2017年10月16日 4:43
すべての返信
-
下記の文書を参考に Registry の 編集を実行してみてください。
Folder Home Pages Aren't Available
https://www.slipstick.com/problems/folder-home-pages-arent-available/
- 回答の候補に設定 栗下 望Microsoft employee, Moderator 2017年10月12日 3:50
- 回答としてマーク takuya_1024 2017年10月16日 4:43
-
FYI
Folder Homepage Settings deprecation
In the October update 10/10/2017 the Folder Homepages setting was deprecated in order to close a security vulnerability.
What was the problem?
When an Exchange mailbox is compromised, e.g. by password spraying, an external attacker can use the Folder Homepage to gain remote code execution within the corporate network by setting the folder homepage to a malicious URL.
The folder homepage roams between clients, which means that an external attacker can set a folder homepage to an arbitrary URL, and then roam that into the Outlook client running within the corporate network.
External publication and exploit tool can be found here https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/
What has changed:
We have disabled reading the folder homepage properties from the folder by default. Since the changing those properties would potentially break other machines that opted-out of this protection, we also disable/hide the property page which would have let the user try to set those properties on the folder.
Work-Around:
If a folder homepage still needs to be set, there are individual registry keys we'll fall back to for each of our special folders and for Outlook Today. The WebView registry keys are specific to default folders. The workaround doesn’t work for folders that the user created and wants to use with a folder homepage.
This does not violate security, since these regkeys do not roam.
There's a registry key customers can set to re-enable roaming folder homepages.
Full documentation of workarounds can be found here (Issue #1) https://support.office.com/en-us/article/Fixes-or-workarounds-for-recent-issues-in-Outlook-for-Windows-ecf61305-f84f-4e13-bb73-95a214ac1230
Those regkeys are:
To turn off folder homepage roaming protection: [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Security] "EnableRoamingFolderHomepages"=dword:00000001
To set a folder home page without disabling protection (replacing Inbox with the folder name): [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\WebView\Inbox] "URL"=http://internalsite/
- 回答の候補に設定 栗下 望Microsoft employee, Moderator 2017年10月16日 0:33
- 回答としてマーク takuya_1024 2017年10月16日 4:43
-
情報のご提供ありがとうございました
・レジストリを編集することで、ホームページタブが表示され編集できることを確認しました
・Yoshikawa様からご提供のあったとおり、悪意のあるURLを設定される可能性を考慮し
この機能を使用しないようにしたい思います
ありがとうございました
- 編集済み takuya_1024 2017年10月16日 4:59 曖昧な表現の修正