2.6.6.6.4 Ensure 'Run Programs' is set to 'Enabled: disable (don't run any programs)'

Information

This policy setting controls the prompting and activation behavior for the Run Programs option for action buttons in PowerPoint.

By choosing the Disable (don't run any programs) option, if users click an action button with the Run Programs action assigned to it, nothing will happen.

The recommended state for this setting is: Enabled: Disable (don't run any programs)

Rationale:

Action buttons can be used to launch external programs from PowerPoint presentations. If a malicious user adds an action button to a presentation that launches a dangerous program, it could affect the security of a user's computer and data.

Impact:

Users who wish to create or use presentations that launch external programs when action buttons are clicked will not be able to do so. These users will have to launch any external programs manually at the appropriate times when delivering presentations.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: disable (don't run any programs).

User Configuration\Administrative Templates\Microsoft PowerPoint 2016\PowerPoint Options\Security\Run Programs

Default Value:

Disabled. (If users click an action with the 'Run Programs' action assigned to it, nothing will happen. This behavior is the same as Enabled -- Disable (don't run any programs).)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(2)

Plugin: Windows

Control ID: 26c343166e47ddfe4c36defc073ebf842ef87294e9f26aee53c57a72ad7541b7