1.1.5.1 Ensure 'Enable Automatic Updates' is set to 'Enabled'

Information

This policy setting controls whether the Office automatic updates are enabled or disabled for all Office products installed by using Click-to-Run.

Note: This policy has no effect on Office products installed via Windows Installer.

The recommended state for this setting is: Enabled.

Rationale:

Security updates help prevent malicious attacks on Office applications. Timely application of Office updates helps ensure the security of devices and the applications running on the devices. Without these updates, devices and the applications running on those devices are more susceptible to security attacks.

Impact:

Office updates for Click-to-Run installations of Microsoft Office are applied in the background and have no adverse affect on users.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

Computer Configuration\Administrative Templates\Microsoft Office 2016 (Machine)\Updates\Enable Automatic Updates

Default Value:

Enabled. (Office periodically checks for updates. When updates are detected, Office downloads and applies them in the background.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2)

Plugin: Windows

Control ID: dd2afab83d9f2a9234f55e9b4a68a6b930f1c4c4f4233443b3773098f4a17690