Skip to content

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000219

    Group
  • The HTTP fallback for SIP connection in Lync must be disabled.

    Prevents from HTTP being used for SIP connection in case TLS or TCP fail.
    Rule Medium Severity
  • SRG-APP-000575

    Group
  • SRG-APP-000575

    Group
  • SRG-APP-000210

    Group
  • Scripts associated with public folders must be prevented from execution in Outlook.

    This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Scripts associated with shared folders must be prevented from execution in Outlook.

    This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders.
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • Files dragged from an Outlook e-mail to the file system must be created in ANSI format.

    This policy setting controls whether e-mail messages dragged from Outlook to the file system are saved in Unicode or ANSI format.
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • SRG-APP-000210

    Group
  • Active X One-Off forms must only be enabled to load with Outlook Controls.

    By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipie...
    Rule Medium Severity
  • SRG-APP-000340

    Group
  • SRG-APP-000516

    Group
  • Internet must not be included in Safe Zone for picture download in Outlook.

    This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so. ...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The Publish to Global Address List (GAL) button must be disabled in Outlook.

    This policy setting controls whether Outlook users can publish e-mail certificates to the Global Address List (GAL). If you enable this policy setting, the "Publish to GAL" button does not displa...
    Rule Medium Severity
  • SRG-APP-000630

    Group
  • SRG-APP-000207

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules