2.3.19.2 (L1) Ensure 'Always expand groups in Office when restricting permission for documents' is set to 'Enabled'

Information

This policy setting controls whether group names automatically expand to display all the members of the group when selected in the Permissions dialog box.

The recommended state for this setting is: Enabled

By default, when users select a group name while applying Information Rights Management (IRM) permissions to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents in the Permissions dialog box, the members of the group are not displayed. This functionality can make it possible for users to unknowingly give read or change permissions to inappropriate people.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Office 2016\Manage Restricted Permissions\Always expand groups in office when restricting permission for documents

Impact:

Enabling this setting changes the way the Permissions dialog box displays names but should not create significant usability issues for most users.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 197e15b97c5668f11b8b19f0cb84d8aa6873382dd335631e9f9adbfb713a4c6d