2.8.4.1.3 (L1) Ensure 'Disable Trust Bar Notification for unsigned application add-ins and block them' is set to 'Enabled'

Information

This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disables such add-ins without notification.

Note: For this policy to apply, the

Require that application add-ins are signed by Trusted Publisher

policy setting needs to be enabled. This will prevent users from changing the

Disable Trust Bar Notification for Unsigned Application Add-ins and Block Them

policy setting.

The recommended state for this setting is: Enabled

Allowing unsigned application add-ins could cause the application to load dangerous add-ins and as a result, malicious code could become active endpoints and the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled

Microsoft Publisher 2016\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher\Disable Trust Bar Notification for unsigned application add-ins and block them

Impact:

If an application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1)

Plugin: Windows

Control ID: 38b9208c5942e6118466d8891ae31629d261ac66b8aab86ee0f0995b23f368e5