7.1 Ensure that the MaxZoneParts setting for Web Part limits is set to 100.

Information

Limit the number of web parts in SharePoint to 100.
Rationale:
A user can create too many personal views. With personal views, SharePoint actually adds each view as a web part on the page. If a user has 10 personal views, there are actually 10 web parts on the page. 9 of those web parts are hidden depending on the personal view selected. When SharePoint reaches the default maximum of 50 web parts on the page, it will throw an error.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Navigate to the IIS Manager on the Web Front End (WFE) servers
1. Click on the Sites folder.
2. Highlight the site (web application).
3. On the right-hand navigation bar, Click on Explore.
4. Open the web.config file with Notepad.
5. Find the following phrase: <WebPartLimits MaxZoneParts='50' PropertySize='1048576'/>.
6. Change the value for MaxZoneParts from 50 to 100.
7. Save the file.
8. Open a command prompt as Administrator and type in iisreset to restart IIS.
9. Repeat for the remaining Web Front End servers.
Impact:
SharePoint will throw errors if the number of web parts is not limited.
Default Value:
50 web parts per page

See Also

https://workbench.cisecurity.org/files/2031

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|18

Plugin: Windows

Control ID: 00517559cad79f086bb1f7ab4e9f6296fc8e6995e18780c012a9772b40d447cc