2.3.23.2 (L1) Ensure 'Block signing into Office' is set to 'Enabled: Org ID only'

Information

This policy setting controls whether users can provide credentials to Office using either their Microsoft Account or the user ID assigned by the organization for accessing Office 365.

By selecting the Org ID only option, users can sign in only by using the user ID assigned by the organization for accessing Office 365.

The recommended state for this setting is: Enabled: Org ID only

If end users are allowed to connect personal Microsoft Accounts to an organization's Office applications, then confidential data could be exfiltrated to the users' personal cloud storage. Likewise, the users' personal data could more easily end up on work-related systems. By restricting Office 365 sign in to Organization ID only, users will also be forced to sign into a tenant that has managed policies and restrictions assigned to them.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Org ID only :

Microsoft Office 2016\Miscellaneous\Block Signing into Office

Impact:

Users will be unable to connect to cloud services not maintained by the organization (such as SharePoint services in Office 365) and access the files and services provided by the cloud services.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-20

Plugin: Windows

Control ID: 138100ada74cd3606dff55dfe969b1de8b2133e887b323bfd1065cd9be35ba81