2.3.18.5 Ensure 'Prevent users from changing permissions on rights managed content' is set to 'Disabled'

Information

This policy setting controls whether Office users can change permissions for content that is protected with Information Rights Management (IRM).

The Information Rights Management feature of Office allows individuals and administrators to specify access permissions to Word documents, Excel workbooks, PowerPoint presentations, InfoPath templates and forms, and Outlook e-mail messages. This functionality helps prevent sensitive information from being printed, forwarded, or copied by unauthorized people.

The recommended state for this setting is: Disabled.

Rationale:

The Information Rights Management feature of the Office release allows individuals and administrators to specify access permissions to Word documents, Excel workbooks, PowerPoint presentations, InfoPath templates and forms, and Outlook e-mail messages. This functionality helps prevent sensitive information from being printed, forwarded, or copied by unauthorized people.

This setting can be used to prevent Office users from changing the IRM permissions of a document. If this setting is Enabled, users can open and edit documents for which they have the appropriate permissions, but they cannot create new rights-managed content, add IRM to existing documents, change existing IRM permissions, or remove IRM from documents. This configuration can prevent users from making effective use of IRM to protect documents

Impact:

Disabling this setting enforces the Office default configuration, and is therefore unlikely to cause significant usability issues for most users.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Manage Restricted Permissions\Prevent Users From Changing Permissions on Rights Managed Content

Default Value:

Disabled. (Users can manage IRM permissions)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2

Plugin: Windows

Control ID: af1da11768df88d71b0f24bad4617c0217e1c9f4974c2c5dd9a73716c8ae7303