DTOO234 - ActiveX One-Off forms must be configured.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2016 -> Security 'Allow Active X One Off Forms' to 'Enabled: Load only Outlook Controls'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Outlook_2016_V2R1_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, CCI|CCI-001170, Rule-ID|SV-228435r508021_rule, STIG-ID|DTOO234, STIG-Legacy|SV-85773, STIG-Legacy|V-71149, Vuln-ID|V-228435

Plugin: Windows

Control ID: 05d5f4e114f43241e9b261baf51713ec451619e8ca05a1351481515dd05a85c0