2.6.6.6.2.5 (L1) Ensure 'Require that application add-ins are signed by Trusted Publisher' is set to 'Enabled'

Information

This policy setting controls whether add-ins for this application must be digitally signed by a trusted publisher.

The recommended state for this setting is: Enabled

By default, Office applications do not check the digital signature on application add-ins before opening them. Not configuring this setting may allow an application to load dangerous add-ins and as a result, malicious code could become active on endpoints or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled

Microsoft PowerPoint 2016\PowerPoint Options\Security\Trust Center\Require that application add-ins are aigned by Trusted Publisher

Impact:

This setting could cause disruptions for users who rely on add-ins that are not signed by trusted publishers. These users will either have to obtain signed versions of such add-ins or stop using them.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1)

Plugin: Windows

Control ID: 5e8170dccfddf9c569898b817d3ec87c9ad73df1423b3118f0784584bfd63d93