2.3.27.8 (L1) Ensure 'Control how Office handles form-based sign-in prompts' is set to 'Enabled: Block all prompts'

Information

This policy setting controls how Office applications handle form-based sign-in prompts.

Office Forms Based Authentication [MS-OFBA] is a protocol used in Office suite applications since Microsoft Office 2007. It provides a method to authenticate to other services via HTTP over a network connection.

Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.

The recommended state for this setting is: Enabled: Block all prompts

Office Forms Based Authentication Protocol is legacy protocol and is disabled in Office by default. It is associated with several exploits such as credential theft and denial of service attacks.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Block all prompts :

Microsoft Office 2016\Security Settings\Control how Office handles form-based sign-in prompts

Impact:

This enforces the default configuration of Office and will only impact users who have already permitted it in the Trust Center.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 09955447560bcf7fc661caac52c0060efaeac523367f220a22196c69ede7dcae