2.17.4 Ensure 'Always Expand Groups in Office When Restricting Permission for Documents' is set to Enabled

Information

This policy setting controls whether group names automatically expand to display all the members of the group when selected in the Permissions dialog box. The recommended state for this setting is: Enabled. By default, when users select a group name while applying Information Rights Management (IRM) permissions to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents in the Permissions dialog box, the members of the group are not displayed. This functionality can make it possible for users to unknowingly give read or change permissions to inappropriate people.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled. User Configuration\Administrative Templates\Microsoft Office 2016\Manage Restricted Permissions\Always Expand Groups in Office When Restricting Permission for Documents Impact: Enabling this setting changes the way the Permissions dialog box displays names, but should not create significant usability issues for most users.

See Also

https://workbench.cisecurity.org/files/571

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 968adbc3fddb9bc907e87ef8fa4cc9f1a7a73e3dbb553eecdb0262fd47f7a7ec