2.3.28.2 Ensure 'Disable the Office client from polling the SharePoint Server for published links' is set to 'Enabled'

Information

This policy setting controls whether Office applications can poll Office servers to retrieve lists of published links.

Note: This policy setting applies to Microsoft SharePoint Server specifically. It does not apply to Microsoft SharePoint Foundation.

The recommended state for this setting is: Enabled.

Rationale:

By default, users of Office applications can see and use links to Microsoft Office SharePoint Server sites from those applications. Administrators configure published links to Office applications during initial deployment, and can add or change links as part of regular operations. These links appear on the My SharePoint Sites tab of the Open, Save, and Save As dialog boxes when opening and saving documents from these applications. Links can be targeted so that they only appear to users who are members of particular audiences.

If a malicious person gains access to the list of published links, they could modify the links to point to unapproved sites, which could make sensitive data vulnerable to exposure.

Impact:

If this setting is Enabled, users will not be able to use the list of published links to open and save files directly from within Office applications, which could hinder the use of SharePoint Server for document collaboration.

Note#2: This setting applies to Microsoft Office SharePoint Server specifically. It does not apply to Windows SharePoint Services (WSS).

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Server Settings\Disable the Office client from polling the SharePoint Server for published links

Default Value:

Disabled. (Users of Office 2016 applications can see and use links to Microsoft SharePoint Server sites from those applications)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: a1e0b07633da11658134cb4ead484fe01e8cc81f4c769c06223c4dbe64ca4b76