Skip to content

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000112

    <GroupDescription></GroupDescription>
    Group
  • File Download Restriction must be enabled in all Office programs.

    &lt;VulnDiscussion&gt;Disabling this setting allows websites to present file download prompts via code without the user specifically initiating the...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • The Save from URL feature must be enabled in all Office programs.

    &lt;VulnDiscussion&gt;Typically, when Internet Explorer loads a web page from a Universal Naming Convention (UNC) share that contains a Mark of the...
    Rule Medium Severity
  • SRG-APP-000112

    <GroupDescription></GroupDescription>
    Group
  • Scripted Windows Security restrictions must be enabled in all Office programs.

    &lt;VulnDiscussion&gt;Malicious websites often try to confuse or trick users into giving a site permission to perform an action allowing the site t...
    Rule Medium Severity
  • SRG-APP-000488

    <GroupDescription></GroupDescription>
    Group
  • Flash player activation must be disabled in all Office programs.

    &lt;VulnDiscussion&gt;This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation block...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Trusted Locations on the network must be disabled in Excel.

    &lt;VulnDiscussion&gt;This policy setting controls whether trusted locations on the network can be used. If you enable this policy setting, users ...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • VBA Macros not digitally signed must be blocked in Excel.

    &lt;VulnDiscussion&gt;This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are pr...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Dynamic Data Exchange (DDE) server launch in Excel must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to control whether Dynamic Data Exchange (DDE) server launch is allowed. By default, DDE serv...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Dynamic Data Exchange (DDE) server lookup in Excel must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to control whether Dynamic Data Exchange (DDE) server lookup is allowed. By default, DDE serv...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of dBase III / IV format files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Dif and Sylk format files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 2 macrosheets and add-in files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 2 worksheets must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 3 macrosheets and add-in files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Extraction options must be blocked when opening corrupt Excel workbooks.

    &lt;VulnDiscussion&gt;This policy setting controls whether Excel presents users with a list of data extraction options before beginning an Open and...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 3 worksheets must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 4 macrosheets and add-in files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 4 workbooks must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 4 worksheets must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 95 workbooks must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 95-97 workbooks and templates must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • The default file block behavior must be set to not open blocked files in Excel.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Web pages and Excel 2003 XML spreadsheets must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Updating of links in Excel must be prompted and not automatic.

    &lt;VulnDiscussion&gt;This policy setting controls whether Excel prompts users to update automatic links, or whether the updates occur in the backg...
    Rule Medium Severity
  • SRG-APP-000488

    <GroupDescription></GroupDescription>
    Group
  • Loading of pictures from Web pages not created in Excel must be disabled.

    &lt;VulnDiscussion&gt;This policy setting controls whether Excel loads graphics when opening Web pages that were not created in Excel. It configure...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • AutoRepublish in Excel must be disabled.

    &lt;VulnDiscussion&gt;This policy setting allows administrators to disable the AutoRepublish feature in Excel. If users choose to publish Excel dat...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules