Skip to content

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Outlook must be configured to prevent users overriding attachment security settings.

    <VulnDiscussion>This policy setting prevents users from overriding the set of attachments blocked by Outlook. If you enable this policy sett...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • Internet must not be included in Safe Zone for picture download in Outlook.

    &lt;VulnDiscussion&gt;This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Inte...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The Publish to Global Address List (GAL) button must be disabled in Outlook.

    &lt;VulnDiscussion&gt;This policy setting controls whether Outlook users can publish e-mail certificates to the Global Address List (GAL). If you...
    Rule Medium Severity
  • SRG-APP-000630

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • The minimum encryption key length in Outlook must be at least 168.

    &lt;VulnDiscussion&gt;This policy setting allows you to set the minimum key length for an encrypted e-mail message. If you enable this policy sett...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • The warning about invalid digital signatures must be enabled to warn Outlook users.

    &lt;VulnDiscussion&gt;This policy setting controls how Outlook warns users about messages with invalid digital signatures. If you enable this poli...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules