1.2.6.1 (L1) Ensure 'Enable Automatic Updates' is set to 'Enabled'

Information

This policy setting controls whether the Office automatic updates are enabled or disabled for all Office products installed by using Click-to-Run.

Note: This policy has no effect on Office products installed via Windows Installer.

The recommended state for this setting is: Enabled

Security updates help prevent malicious attacks on Office applications. Timely application of Office updates helps ensure the security of devices and the applications running on the devices. Without these updates, devices and the applications running on those devices are more susceptible to security attacks.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled

Microsoft Office 2016 (Machine)\Updates\Enable Automatic Updates

Impact:

Office updates for Click-to-Run installations of Microsoft Office are applied in the background and have no adverse effect on users.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2)

Plugin: Windows

Control ID: fd1b3ecae786a1c54203530d9e6b6ea11afa07dde5ed8bf0eb9dba80a8a55099