2.17.2 Ensure 'Never Allow Users to Specify Groups When Restricting Permission for Documents' is set to Enabled

Information

This policy setting controls whether Office users can assign permissions to distribution lists when using Information Rights Management. The recommended state for this setting is: Enabled. By default, Office users can specify distribution lists when using Information Rights Management (IRM) to restrict access to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents. If users are not fully aware of the distribution list's membership before assigning it permission to open or modify a document, sensitive information could be at risk.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled. User Configuration\Administrative Templates\Microsoft Office 2016\Manage Restricted Permissions\Never Allow Users to Specify Groups When Restricting Permission for Documents Impact: Enabling this setting could cause some disruptions for Office users who are accustomed to specifying distribution groups when defining permissions for a document. These users will have to list users individually in the Permission dialog box to assign them permission to read or modify the document. Users who do not use Information Rights Management will not be affected by this setting.

See Also

https://workbench.cisecurity.org/files/571

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Windows

Control ID: 1314ac6e86f4d89b52f5d3320df93499c6220947b3a4a05d64fba1a91c19cd4d