2.6.6.6.4 (L1) Ensure 'Run Programs' is set to 'Enabled: disable (don't run any programs)'

Information

This policy setting controls the prompting and activation behavior for the

Run Programs

option for action buttons in PowerPoint.

By choosing the Disable (don't run any programs) option, if users click an action button with the

Run Programs

action assigned to it, nothing will happen.

The recommended state for this setting is: Enabled: Disable (don't run any programs)

Action buttons can be used to launch external programs from PowerPoint presentations. If a malicious user adds an action button to a presentation that launches a dangerous program, it could affect the security of a user's computer and data.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: disable (don't run any programs)

Microsoft PowerPoint 2016\PowerPoint Options\Security\Run Programs

Impact:

Users who wish to create or use presentations that launch external programs when action buttons are clicked will not be able to do so. These users will have to launch any external programs manually at the appropriate times when delivering presentations.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(2)

Plugin: Windows

Control ID: 16a4d84ca0e95d3905242137c0b98e7de63c04edb39982c47110f83c2979ee69