2.5.14.5 Ensure 'Allow Active X One Off Forms' is set to 'Enabled: Load only Outlook Controls'

Information

This policy setting configures the use of third-party ActiveX controls in Outlook. This setting can can be configured so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.

The recommended state for this setting is: Enabled: Load only Outlook Controls.

Rationale:

If additional types of Active X controls are allowed, particularly un-trusted third-party controls, the risk of malware infecting the computer increases.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Load only Outlook Controls:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Allow Active X One Off Forms

Default Value:

(Third-party ActiveX controls are not allowed to run in one-off forms in Outlook.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18

Plugin: Windows

Control ID: 8cea48868508ddd5a9d309be96af971f35cfe376cc67224c2be3c6600f3bfefc