Skip to content

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Flash player activation must be disabled in all Office programs.

    <VulnDiscussion>This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation block...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Trusted Locations on the network must be disabled in Excel.

    &lt;VulnDiscussion&gt;This policy setting controls whether trusted locations on the network can be used. If you enable this policy setting, users ...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • VBA Macros not digitally signed must be blocked in Excel.

    &lt;VulnDiscussion&gt;This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are pr...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • The SIP security mode in Lync must be enabled.

    &lt;VulnDiscussion&gt;When Lync connects to the server, it supports various authentication mechanisms. This policy allows the user to specify wheth...
    Rule Medium Severity
  • SRG-APP-000219

    <GroupDescription></GroupDescription>
    Group
  • The HTTP fallback for SIP connection in Lync must be disabled.

    &lt;VulnDiscussion&gt;Prevents from HTTP being used for SIP connection in case TLS or TCP fail.&lt;/VulnDiscussion&gt;&lt;FalsePositives&gt;&lt;/Fa...
    Rule Medium Severity
  • SRG-APP-000575

    <GroupDescription></GroupDescription>
    Group
  • Dynamic Data Exchange (DDE) server launch in Excel must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to control whether Dynamic Data Exchange (DDE) server launch is allowed. By default, DDE serv...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Dynamic Data Exchange (DDE) server lookup in Excel must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to control whether Dynamic Data Exchange (DDE) server lookup is allowed. By default, DDE serv...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of dBase III / IV format files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Dif and Sylk format files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group
  • Open/save of Excel 2 macrosheets and add-in files must be blocked.

    &lt;VulnDiscussion&gt;This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified...
    Rule Medium Severity
  • SRG-APP-000207

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules