2.3.27.8 Ensure 'Control how Office handles form-based sign-in prompts' is set to 'Enabled: Block all prompts'

Information

This policy setting controls how Office applications handle form-based sign-in prompts.

Office Forms Based Authentication [MS-OFBA] is a protocol used in Office suite applications since Microsoft Office 2007. It provides a method to authenticate to other services via HTTP over a network connection.

Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.

The recommended state for this setting is: Enabled: Block all prompts

Rationale:

Office Forms Based Authentication Protocol is legacy protocol, and is disabled in Office by default. It is associated with several exploits such as credential theft and denial of service attacks.

Impact:

This enforces the default configuration of Office and will only impact users who have already permitted it in the Trust Center.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Block all prompts:

User Configuration\Administrative Templates\Microsoft Office 2016\Security Settings\Control how Office handles form-based sign-in prompts

Default Value:

Disabled. (Form-based sign-in prompts are blocked but users can override.)

See Also

https://workbench.cisecurity.org/benchmarks/18612

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: d1b537e2b0c4b1a0ac99d32eed6af0b30b5232bee8d68dc14842290cab7ad979