Skip to content

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Files from unsafe locations must be opened in Excel in Protected View mode.

    &lt;VulnDiscussion&gt;This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not spec...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Outlook must be configured to prevent users overriding attachment security settings.

    &lt;VulnDiscussion&gt;This policy setting prevents users from overriding the set of attachments blocked by Outlook. If you enable this policy sett...
    Rule Medium Severity
  • Files failing file validation must be opened in Excel in Protected view mode and disallow edits.

    &lt;VulnDiscussion&gt;This policy setting controls how Office handles documents when they fail file validation. If you enable this policy setting...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • File attachments from Outlook must be opened in Excel in Protected mode.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine if Excel files in Outlook attachments open in Protected View. If you enable this...
    Rule Medium Severity
  • SRG-APP-000219

    <GroupDescription></GroupDescription>
    Group
  • The SIP security mode in Lync must be enabled.

    &lt;VulnDiscussion&gt;When Lync connects to the server, it supports various authentication mechanisms. This policy allows the user to specify wheth...
    Rule Medium Severity
  • SRG-APP-000219

    <GroupDescription></GroupDescription>
    Group
  • The HTTP fallback for SIP connection in Lync must be disabled.

    &lt;VulnDiscussion&gt;Prevents from HTTP being used for SIP connection in case TLS or TCP fail.&lt;/VulnDiscussion&gt;&lt;FalsePositives&gt;&lt;/Fa...
    Rule Medium Severity
  • SRG-APP-000575

    <GroupDescription></GroupDescription>
    Group
  • The Exchange client authentication with Exchange servers must be enabled to use Kerberos Password Authentication.

    &lt;VulnDiscussion&gt;This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note: E...
    Rule Medium Severity
  • SRG-APP-000575

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • Outlook must use remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers.

    &lt;VulnDiscussion&gt;This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchan...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Scripts associated with public folders must be prevented from execution in Outlook.

    &lt;VulnDiscussion&gt;This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for ...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Scripts associated with shared folders must be prevented from execution in Outlook.

    &lt;VulnDiscussion&gt;This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared fo...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules