2.21.3 Ensure 'Block Signing into Office' is set to Enabled (None allowed)

Information

This policy setting controls whether users can provide credentials to Office using either their Microsoft Account or the user ID assigned by your organization for accessing Office 365. The recommended state for this setting is: Enabled. Signing into Office allows users to connect to cloud services (such as SharePoint services in Office 365). By signing into Office, the user's status and other information could be made publicly available. In addition, organizations may not want users to access cloud services because of the potential downloading of malware or uploading of confidential information to cloud services. For example, a user could upload a highly confidential document from the organization's intranet to OneDrive and then share that file with other users on the Internet.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled. User Configuration\Administrative Templates\Microsoft Office 2016\Miscellaneous\Block Signing into Office Impact: Users will not be unable to connect to cloud services (such as SharePoint services in Office 365) and access the files and services provided by the cloud services.

See Also

https://workbench.cisecurity.org/files/571

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-20

Plugin: Windows

Control ID: 4bb838dea5704d22221badf560b7ef8e7e65a5c1652a513a6c855b9aedb2fa1f