6.11 Set 'Never allow users to specify groups when restricting permission for documents' to 'Enabled'

Information

This policy setting controls whether Office 2010 users can assign permissions to
distribution lists when using Information Rights Management. If you enable this policy
setting, Office 2010 users cannot specify a distribution list as an authorized party in the
Permission dialog box. If you disable or do not configure this policy setting, Office 2010
users can specify distribution lists when using Information Rights Management (IRM) to
restrict access to Excel workbooks, InfoPath templates, Outlook e-mail messages,
PowerPoint presentations, or Word documents. The recommended state for this setting is-
Enabled.

*Rationale*

By default, Office 2010 users can specify distribution lists when using Information Rights
Management (IRM) to restrict access to Excel 2010 workbooks, InfoPath 2010 templates,
Outlook 2010 e-mail messages, PowerPoint 2010 presentations, or Word 2010 documents.
If users are not fully aware of the distribution list's membership before assigning it
permission to open or modify a document, sensitive information could be at risk.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

User Configuration\Administrative Templates\Microsoft Office 2010\Manage Restricted
Permissions\Never allow users to specify groups when restricting permission for
documents

Impact-Enabling this setting could cause some disruptions for Office 2010 users who are
accustomed to specifying distribution groups when defining permissions for a document.
These users will have to list users individually in the Permission dialog box to assign them
permission to read or modify the document. Users who do not use Information Rights
Management will not be affected by this setting.

See Also

https://workbench.cisecurity.org/files/530

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Windows

Control ID: b88211413f5579d14742a294cbbede9b5789a083ec4206bcb950ee987ce1a3a0