Skip to content

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Publisher must be configured to prompt the user when another application programmatically opens a macro.

    &lt;VulnDiscussion&gt;This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are lo...
    Rule Medium Severity
  • SRG-APP-000131

    <GroupDescription></GroupDescription>
    Group
  • Publisher must automatically disable unsigned add-ins without informing users.

    &lt;VulnDiscussion&gt;This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are lo...
    Rule Medium Severity
  • SRG-APP-000131

    <GroupDescription></GroupDescription>
    Group
  • Publisher must disable all unsigned VBA macros.

    &lt;VulnDiscussion&gt;This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are pr...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Visio 5.0 or earlier Binary Drawings, Templates and Stencils must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title...
    Rule Medium Severity
  • VBA Macros not digitally signed must be blocked in Visio.

    &lt;VulnDiscussion&gt;This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are pr...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Trusted Locations on the network must be disabled in Visio.

    &lt;VulnDiscussion&gt;This policy setting controls whether trusted locations on the network can be used. If you enable this policy setting, users ...
    Rule Medium Severity
  • SRG-APP-000131

    <GroupDescription></GroupDescription>
    Group
  • Visio must automatically disable unsigned add-ins without informing users.

    &lt;VulnDiscussion&gt;This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are lo...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Visio 2000-2002 Binary Drawings, Templates and Stencils must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Visio 2003-2010 Binary Drawings, Templates and Stencils must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules