2.8.4.2 (L1) Ensure 'Publisher Automation Security Level' is set to 'Enabled: By UI (prompted)'

Information

This policy setting controls whether macros opened programmatically by another application can run in Publisher and how those macros will run.

The recommended state for this setting is: By UI (prompted)

Note: With the above macro functionality configuration selected, macro behavior will be determined by the setting

VBA Macro Notification Settings

in the Trust Center.

Users may enable macros which could execute malicious code and cause a virus to load undetected.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: By UI (prompted) :

Microsoft Publisher 2016\Security\Publisher Automation Security Level

Impact:

This configuration causes documents and templates that contain unsigned macros to lose all functionality supplied by the macro. To prevent this loss of functionality, users can install the macro in a trusted location, unless the

Disable all trusted locations

setting is configured to

Enabled

, which will not allow the user to add to the trusted location.

Warning: With the

Disable all except digitally signed macros

option selected, users will not be able to open unsigned Access databases.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 3100dc196f0c0dccbcf39a35bc1d40b0aeee3c496c7b944f13f01269760320a9