Information
This setting controls the encryption mode that Office uses to protect content with Information Rights Management.
- For Microsoft 365 Apps (Version 2304 or later): Cipher Block Chaining (CBC) mode is used
- For earlier Microsoft 365 Apps and Office LTSC 2021, 2019, and 2016: Electronic Codebook (ECB) mode is used
The recommended state for this setting is: Enabled: Cipher Block Chaining (CBC)
Electronic Codebook (ECB) has several weaknesses, such as the lack of diffusion, determinism, and susceptibility to pattern attacks. As a result, organizations like NIST and ISO recommend against its use.
To ensure a higher level of security, Cipher Block Chaining (CBC) can be enforced. This block cipher mode will be used to encrypt IRM content with applications like Excel, PowerPoint, Word, Visio, or Outlook, regardless of their versions.
Solution
To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Cipher Block Chaining (CBC) :
Microsoft Office 2016\Security Settings\Encryption mode for Information Rights Management (IRM)
Impact:
There is no impact or additional overhead associated with using CBC over ECB.