2.3.18.3 Ensure 'Always require users to connect to verify permission' is set to 'Enabled'

Information

This policy setting controls whether users are required to connect to the Internet or a local network to have their licenses confirmed every time they attempt to open Excel workbooks, InfoPath forms or templates, Outlook e-mail messages, PowerPoint presentations, or Word documents that are protected by Information Rights Management (IRM). This policy is useful for logging the usage of files with restricted permissions on the server.

The recommended state for this setting is: Enabled.

Rationale:

By default, users are not required to connect to the network to verify permissions. If users do not need their licenses confirmed when attempting to open Office documents, they might be able to access documents after their licenses have been revoked. Also, it is not possible to log the usage of files with restricted permissions if users' licenses are not confirmed.

Impact:

Enabling this setting could create problems for users who need to open rights-managed files when they are not connected to the Internet, such as mobile users. Consider surveying the organization to determine users' need for offline use of rights-managed files before enabling this setting.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Manage Restricted Permissions\Always require users to connect to verify permission

Default Value:

Disabled. (Users are not required to connect.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 24427ef9476dd4c12d180cff19063c27bb8c3fb71aaf25b3a4e4946232f54de7