STIGQter STIGQter: STIG Summary:

Microsoft Office 365 ProPlus Security Technical Implementation Guide

Version: 3

Release: 5 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-223280r961050_ruleMacros must be blocked from running in Access files from the Internet.
SV-223281r1016166_ruleTrust Bar Notifications for unsigned application add-ins in Access must be disabled and blocked.
SV-223282r1082349_ruleVBA macros not digitally signed must be blocked in Access.
SV-223284r961092_ruleThe Macro Runtime Scan Scope must be enabled for all documents.
SV-223285r1067544_ruleDocument metadata for rights managed Office Open XML files must be protected.
SV-223286r960963_ruleThe Office client must be prevented from polling the SharePoint Server for published links.
SV-223287r961863_ruleCustom user interface (UI) code must be blocked from loading in all Office applications.
SV-223288r961779_ruleActiveX Controls must be initialized in Safe Mode.
SV-223289r961092_ruleMacros in all Office applications that are opened programmatically by another application must be opened based upon macro security level.
SV-223290r1016167_ruleTrust Bar notifications must be configured to display information in the Message Bar about the content that has been automatically blocked.
SV-223291r961128_ruleOffice applications must be configured to specify encryption type in password-protected Office 97-2003 files.
SV-223292r961128_ruleOffice applications must be configured to specify encryption type in password-protected Office Open XML files.
SV-223293r961353_ruleUsers must be prevented from creating new trusted locations in the Trust Center.
SV-223294r961863_ruleOffice applications must not load XML expansion packs with Smart Documents.
SV-223295r961086_ruleThe load of controls in Forms3 must be blocked.
SV-223296r961086_ruleAdd-on Management must be enabled for all Office 365 ProPlus programs.
SV-223297r961050_ruleConsistent MIME handling must be enabled for all Office 365 ProPlus programs.
SV-223298r961092_ruleUser name and password must be disabled in all Office programs.
SV-223299r961086_ruleThe Information Bar must be enabled in all Office programs.
SV-223300r961863_ruleThe Local Machine Zone Lockdown Security must be enabled in all Office programs.
SV-223301r961050_ruleThe MIME Sniffing safety feature must be enabled in all Office programs.
SV-223302r961092_ruleNavigate URL must be enabled in all Office programs.
SV-223303r961050_ruleObject Caching Protection must be enabled in all Office programs.
SV-223304r960921_ruleProtection from zone elevation must be enabled in all Office programs.
SV-223305r961779_ruleActiveX installation restriction must be enabled in all Office programs.
SV-223306r960921_ruleFile Download Restriction must be enabled in all Office programs.
SV-223307r961092_ruleThe Save from URL feature must be enabled in all Office programs.
SV-223308r960921_ruleScripted Windows Security restrictions must be enabled in all Office programs.
SV-223309r961779_ruleFlash player activation must be disabled in all Office programs.
SV-223310r961092_ruleTrusted Locations on the network must be disabled in Excel.
SV-223311r960963_ruleVBA Macros not digitally signed must be blocked in Excel.
SV-223312r961086_ruleDynamic Data Exchange (DDE) server launch in Excel must be blocked.
SV-223313r961086_ruleDynamic Data Exchange (DDE) server lookup in Excel must be blocked.
SV-223314r961086_ruleOpen/save of dBase III / IV format files must be blocked.
SV-223315r961086_ruleOpen/save of Dif and Sylk format files must be blocked.
SV-223316r961086_ruleOpen/save of Excel 2 macrosheets and add-in files must be blocked.
SV-223317r961086_ruleOpen/save of Excel 2 worksheets must be blocked.
SV-223318r961086_ruleOpen/save of Excel 3 macrosheets and add-in files must be blocked.
SV-223319r961086_ruleOpen/save of Excel 3 worksheets must be blocked.
SV-223320r961086_ruleOpen/save of Excel 4 macrosheets and add-in files must be blocked.
SV-223321r961086_ruleOpen/save of Excel 4 workbooks must be blocked.
SV-223322r961086_ruleOpen/save of Excel 4 worksheets must be blocked.
SV-223323r961086_ruleOpen/save of Excel 95 workbooks must be blocked.
SV-223324r961086_ruleOpen/save of Excel 95-97 workbooks and templates must be blocked.
SV-223325r961086_ruleThe default file block behavior must be set to not open blocked files in Excel.
SV-223326r961086_ruleOpen/save of Web pages and Excel 2003 XML spreadsheets must be blocked.
SV-223327r961086_ruleExtraction options must be blocked when opening corrupt Excel workbooks.
SV-223328r961092_ruleUpdating of links in Excel must be prompted and not automatic.
SV-223329r961779_ruleLoading of pictures from Web pages not created in Excel must be disabled.
SV-223330r961863_ruleAutoRepublish in Excel must be disabled.
SV-223331r961863_ruleAutoRepublish warning alert in Excel must be enabled.
SV-223332r961863_ruleFile extensions must be enabled to match file types in Excel.
SV-223333r961092_ruleScan of encrypted macros in Excel Open XML workbooks must be enabled.
SV-223334r960921_ruleFile validation in Excel must be enabled.
SV-223335r961086_ruleWEBSERVICE Function Notification in Excel must be configured to disable all, with notifications.
SV-223336r961092_ruleMacros must be blocked from running in Excel files from the Internet.
SV-223337r1016168_ruleTrust Bar notification must be enabled for unsigned application add-ins in Excel and blocked.
SV-223338r961086_ruleUntrusted Microsoft Query files must be blocked from opening in Excel.
SV-223339r961086_ruleUntrusted database files must be opened in Excel in Protected View mode.
SV-223340r961086_ruleFiles from Internet zone must be opened in Excel in Protected View mode.
SV-223341r961092_ruleFiles from unsafe locations must be opened in Excel in Protected View mode.
SV-223342r961092_ruleFiles failing file validation must be opened in Excel in Protected view mode and disallow edits.
SV-223343r961092_ruleFile attachments from Outlook must be opened in Excel in Protected mode.
SV-223344r1043178_ruleThe SIP security mode in Lync must be enabled.
SV-223345r1043178_ruleThe HTTP fallback for SIP connection in Lync must be disabled.
SV-223346r961878_ruleThe Exchange client authentication with Exchange servers must be enabled to use Kerberos Password Authentication.
SV-223347r961878_ruleOutlook must use remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers.
SV-223348r961092_ruleScripts associated with public folders must be prevented from execution in Outlook.
SV-223349r961092_ruleScripts associated with shared folders must be prevented from execution in Outlook.
SV-223350r961863_ruleFiles dragged from an Outlook e-mail to the file system must be created in ANSI format.
SV-223351r1188335_ruleThe junk email protection level must be set to No Automatic Filtering.
SV-223352r961092_ruleActive X One-Off forms must only be enabled to load with Outlook Controls.
SV-223353r961353_ruleOutlook must be configured to prevent users overriding attachment security settings.
SV-223354r961863_ruleInternet must not be included in Safe Zone for picture download in Outlook.
SV-223355r961863_ruleThe Publish to Global Address List (GAL) button must be disabled in Outlook.
SV-223356r1117184_ruleThe minimum encryption key length in Outlook must be at least 168.
SV-223357r961086_ruleThe warning about invalid digital signatures must be enabled to warn Outlook users.
SV-223358r961893_ruleOutlook must be configured to allow retrieving of Certificate Revocation Lists (CRLs) always when online.
SV-223359r961863_ruleThe Outlook Security Mode must be enabled to always use the Outlook Security Group Policy.
SV-223360r961086_ruleThe ability to demote attachments from Level 2 to Level 1 must be disabled.
SV-223361r961086_ruleThe display of Level 1 attachments must be disabled in Outlook.
SV-223362r961086_ruleLevel 1 file attachments must be blocked from being delivered.
SV-223363r961086_ruleLevel 2 file attachments must be blocked from being delivered.
SV-223364r961092_ruleOutlook must be configured to not run scripts in forms in which the script and the layout are contained within the message.
SV-223365r961779_ruleWhen a custom action is executed that uses the Outlook object model, Outlook must automatically deny it.
SV-223366r961779_ruleWhen an untrusted program attempts to programmatically access an Address Book using the Outlook object model, Outlook must automatically deny it.
SV-223367r961779_ruleWhen a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field, Outlook must automatically deny it.
SV-223368r961779_ruleWhen an untrusted program attempts to use the Save As command to programmatically save an item, Outlook must automatically deny it.
SV-223369r961779_ruleWhen an untrusted program attempts to gain access to a recipient field, such as the, To: field, using the Outlook object model, Outlook must automatically deny it.
SV-223370r961779_ruleWhen an untrusted program attempts to programmatically send e-mail in Outlook using the Response method of a task or meeting request, Outlook must automatically deny it.
SV-223371r961779_ruleWhen an untrusted program attempts to send e-mail programmatically using the Outlook object model, Outlook must automatically deny it.
SV-223372r961863_ruleOutlook must be configured to not allow hyperlinks in suspected phishing messages.
SV-223373r961086_ruleThe Security Level for macros in Outlook must be configured to Warn for signed and disable unsigned.
SV-223374r961092_ruleTrusted Locations on the network must be disabled in Project.
SV-223375r1016169_ruleProject must automatically disable unsigned add-ins without informing users.
SV-223376r960963_ruleVBA Macros not digitally signed must be blocked in Project.
SV-223377r960963_ruleVBA Macros not digitally signed must be blocked in PowerPoint.
SV-223378r961092_ruleThe ability to run programs from PowerPoint must be disabled.
SV-223379r961086_ruleOpen/Save of PowerPoint 97-2003 presentations, shows, templates, and add-in files must be blocked.
SV-223380r961086_ruleThe default file block behavior must be set to not open blocked files in PowerPoint.
SV-223381r961092_ruleEncrypted macros in PowerPoint Open XML presentations must be scanned.
SV-223382r961092_ruleFile validation in PowerPoint must be enabled.
SV-223383r961092_ruleMacros from the Internet must be blocked from running in PowerPoint.
SV-223384r1016170_ruleUnsigned add-ins in PowerPoint must be blocked with no Trust Bar Notification to the user.
SV-223385r961086_ruleFiles downloaded from the Internet must be opened in Protected view in PowerPoint.
SV-223386r961086_rulePowerPoint attachments opened from Outlook must be in Protected View.
SV-223387r961086_ruleFiles in unsafe locations must be opened in Protected view in PowerPoint.
SV-223388r961092_ruleIf file validation fails, files must be opened in Protected view in PowerPoint with ability to edit disabled.
SV-223389r961092_ruleThe use of network locations must be ignored in PowerPoint.
SV-223390r961086_rulePublisher must be configured to prompt the user when another application programmatically opens a macro.
SV-223391r1016171_rulePublisher must automatically disable unsigned add-ins without informing users.
SV-223392r1016172_rulePublisher must disable all unsigned VBA macros.
SV-223393r960963_ruleVBA Macros not digitally signed must be blocked in Visio.
SV-223394r961092_ruleTrusted Locations on the network must be disabled in Visio.
SV-223395r1016173_ruleVisio must automatically disable unsigned add-ins without informing users.
SV-223396r961086_ruleVisio 2000-2002 Binary Drawings, Templates and Stencils must be blocked.
SV-223397r961086_ruleVisio 2003-2010 Binary Drawings, Templates and Stencils must be blocked.
SV-223398r961086_ruleVisio 5.0 or earlier Binary Drawings, Templates and Stencils must be blocked.
SV-223399r961092_ruleMacros must be blocked from running in Visio files from the Internet.
SV-223400r1016174_ruleWord must automatically disable unsigned add-ins without informing users.
SV-223401r961092_ruleIn Word, encrypted macros must be scanned.
SV-223402r961086_ruleFiles downloaded from the Internet must be opened in Protected view in Word.
SV-223403r961086_ruleFiles located in unsafe locations must be opened in Protected view in Word.
SV-223404r961086_ruleIf file validation fails, files must be opened in Protected view in Word with ability to edit disabled.
SV-223405r961086_ruleWord attachments opened from Outlook must be in Protected View.
SV-223406r961086_ruleThe default file block behavior must be set to not open blocked files in Word.
SV-223407r961086_ruleOpen/Save of Word 2 and earlier binary documents and templates must be blocked.
SV-223408r961086_ruleOpen/Save of Word 2000 binary documents and templates must be blocked.
SV-223409r961086_ruleOpen/Save of Word 2003 binary documents and templates must be blocked.
SV-223410r961086_ruleOpen/Save of Word 2007 and later binary documents and templates must be blocked.
SV-223411r961086_ruleOpen/Save of Word 6.0 binary documents and templates must be blocked.
SV-223412r961086_ruleOpen/Save of Word 95 binary documents and templates must be blocked.
SV-223413r961086_ruleOpen/Save of Word 97 binary documents and templates must be blocked.
SV-223414r961086_ruleOpen/Save of Word XP binary documents and templates must be blocked.
SV-223415r961092_ruleIn Word, macros must be blocked from running, even if Enable all macros is selected in the Macro Settings section of the Trust Center.
SV-223416r961092_ruleTrusted Locations on the network must be disabled in Word.
SV-223417r960963_ruleVBA Macros not digitally signed must be blocked in Word.
SV-223418r960921_ruleFile validation in Word must be enabled.
SV-278355r1152352_ruleSending of diagnostic data to Microsoft must be disabled.