2.3.18.2 Ensure 'Always expand groups in Office when restricting permission for documents' is set to 'Enabled'

Information

This policy setting controls whether group names automatically expand to display all the members of the group when selected in the Permissions dialog box.

The recommended state for this setting is: Enabled.

Rationale:

By default, when users select a group name while applying Information Rights Management (IRM) permissions to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents in the Permissions dialog box, the members of the group are not displayed. This functionality can make it possible for users to unknowingly give read or change permissions to inappropriate people.

Impact:

Enabling this setting changes the way the Permissions dialog box displays names, but should not create significant usability issues for most users.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Manage Restricted Permissions\Always expand groups in office when restricting permission for documents

Default Value:

Disabled. (Members of group are not displayed.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 16eb35aefb904efb3375175399c73a93a42131e00af0873b7e9a8dcc980a9a08