STIGQter STIGQter: STIG Summary: Microsoft Office 365 ProPlus Security Technical Implementation Guide Version: 3 Release: 5 Benchmark Date: 01 Apr 2026:

Sending of diagnostic data to Microsoft must be disabled.

DISA Rule

SV-278355r1152352_rule

Vulnerability Number

V-278355

Group Title

SRG-APP-000141

Rule Version

O365-CO-000028

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Configure the level of client software diagnostic data sent by Office to Microsoft" to "Enabled" and select "Neither" from the Options.

Check Contents

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Configure the level of client software diagnostic data sent by Office to Microsoft" is set to "Enabled", and "Neither" from the Options is selected.

Use the Windows Registry Editor to navigate to the following key:
HKCU\software\policies\Microsoft\office\common\clienttelemetry

If the value "SendTelemetry" is "REG_DWORD = 3", this is not a finding.

If the registry key does not exist or is not configured properly, this is a finding.

Vulnerability Number

V-278355

Documentable

False

Rule Version

O365-CO-000028

Severity Override Guidance

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Configure the level of client software diagnostic data sent by Office to Microsoft" is set to "Enabled", and "Neither" from the Options is selected.

Use the Windows Registry Editor to navigate to the following key:
HKCU\software\policies\Microsoft\office\common\clienttelemetry

If the value "SendTelemetry" is "REG_DWORD = 3", this is not a finding.

If the registry key does not exist or is not configured properly, this is a finding.

Check Content Reference

M

Target Key

4099