Restrict legacy JScript execution for Office - mspub.exe

Information

This policy setting controls JScript execution per Security Zone within Internet Explorer and WebBrowser Control (WebOC) for Office applications.

It's important to determine whether legacy JScript is being used to provide business-critical functionality before you enable this setting.

If Enabled Office applications will not execute legacy JScript for the Internet or Restricted Sites zones and users aren't notified by the application that legacy JScript execution is restricted. Modern JScript9 will continue to function for all zones.

If Disabled or Not Configured JScript will function without any restrictions.

The values are set in hexadecimal and should be converted prior to changing the setting value. To learn more about Internet Explorer Feature Control Key and the Restrict JScript process-level policy for Windows please refer to: https://docs.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/general-info/ee330734(v=vs.85)#restrict-jscript-at-a-process-level

Solution

Policy Path: MS Security Guide
Policy Setting Name: Restrict legacy JScript execution for Office

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-for-microsoft-365-apps-for-enterprise-v2112/ba-p/3038172

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3

Plugin: Windows

Control ID: b9749cc272dcf3dfe7f6efd431609262d4e00e1f4db79cbad1ade529c5a6a1e5