1.3.1 Ensure 'Block Flash activation in Office documents' is set to 'Enabled: Block all activation'

Information

This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation blocking applies only within Office processes.

'Block all activation' prevents the Flash control from being loaded, whether directly referenced by the document or indirectly by another embedded object.

The recommended state for this setting is: Enabled: Block all activation.

Rationale:

Adobe Flash was discontinued in 2020. Flash content has had a long history of exploitation by malicious software developers. Blocking will ensure Office does not execute any Flash content. Enforcing the default ensures that the system was not configured in an insecure way.

Impact:

None - this enforces the default behavior of Microsoft Office.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Block all activation.

Computer Configuration\Administrative Templates\MS Security Guide\Block Flash activation in Office documents

Note: This Group Policy path does not exist by default. An additional Group Policy template (SecGuide.admx/adml) is required - it is available from Microsoft at this link.

Default Value:

Flash content is allowed by default, equivalent to Enabled: Allow all activation

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10

Plugin: Windows

Control ID: 5ef87a26c6e2fb0d5478fda1ccd93cc3c2fa623e911698345f7e2628986123df