7.1 Ensure that the MaxZoneParts setting for Web Parts is configured

Information

Limit the number of web parts in SharePoint to a minimum value that is needed.

Rationale:

A user can create too many personal views. With personal views, SharePoint actually adds
each view as a web part on the page. If a user has 10 personal views, there are actually 10
web parts on the page. 9 of those web parts are hidden depending on the personal view
selected. When SharePoint reaches the default maximum of 50 web parts on the page, it
will throw an error.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Navigate to the IIS Manager on the Web Front End (WFE) servers

1. Click on the Sites folder.
2. Highlight the site (web application).
3. On the right-hand navigation bar, Click on Explore.
4. Open the web.config file with Notepad.

5. Find the following phrase: <WebPartLimits MaxZoneParts='50'
PropertySize='1048576'/>.
6. Change the value for MaxZoneParts to a minimum allowed value.
7. Save the file.
8. Open a command prompt as Administrator and type in iisreset to restart IIS.
9. Repeat for the remaining Web Front End servers.

Impact:

SharePoint will throw errors if the number of web parts is not limited.

Default Value:

50 web parts per page

See Also

https://workbench.cisecurity.org/files/2395

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|18

Plugin: Windows

Control ID: 0e6813eecb3192f09fb2585d0ce8218d9c647ba1b83ae4b502f3fb5376ce502d