2.5.14.3.5 (L1) Ensure 'Allow Active X One Off Forms' is set to 'Enabled: Load only Outlook Controls'

Information

This policy setting configures the use of third-party ActiveX controls in Outlook. This setting can can be configured so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.

The recommended state for this setting is: Enabled: Load only Outlook Controls

If additional types of Active X controls are allowed, particularly untrusted third-party controls, the risk of malware infecting the computer increases.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Load only Outlook Controls :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Allow Active X One Off Forms

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18

Plugin: Windows

Control ID: 7bbc3ec4e3bda630204f5957c636b15d69af9465c828205c07cad76493118423