6.6 Set 'Disable UI extending from documents and templates: Disallow in Outlook' to 'Enabled:True'

Information

This policy setting controls whether Office 2010 applications load any custom user
interface (UI) code included with a document or template. Office 2010 allows developers to
extend the UI with customization code that is included in a document or template.
If you enable this policy setting, Office 2010 applications cannot load any UI customization
code included with documents and templates.
If you disable or do not configure this policy setting, Office 2010 applications load any UI
customization code included with a document or template when opening it. The
recommended state for this setting is- Enabled-True.

*Rationale*

The Office 2010 release allows developers to extend the UI with customization code that is
included in a document or template. If the customization code is written by an
inexperienced or malicious developer, it could limit the accessibility or availability of
important application commands. Commands could also be added that launch macros that
contain malicious code.By default, Office applications load any UI customization code included with a document or
template when opening it.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

User Configuration\Administrative Templates\Microsoft Office 2010\Global
Options\Customize\Disable UI extending from documents and templates\Disable UI
extending from documents and templates

Then set the Disable UI extending from documents and templates- Disallow in
Outlook option to True.

Impact-Enabling this setting will prevent developers from using documents and templates to
extend the UI, which some organizations do to increase user productivity. If your
organization makes use of a modified UI, it might not be feasible for you to enable this
setting. Sometimes only specific teams in an organization require a modified UI, and this
setting could be enabled for the rest of the organization.

See Also

https://workbench.cisecurity.org/files/530

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 6ad5aca5c9878b9b06bdce548180aea97cbc486ce5f1e5bdbc5c4f8db6292420