2.3.36.1.1 Ensure 'Conversion Service Options' is set to 'Enabled: Do not allow to use Microsoft Conversion Service'

Information

This policy setting controls users' access to the online features of Office 2016.

The recommended state for this setting is: Enabled: Do not allow to use Microsoft Conversion Service

Rationale:

In a high security environment data should never be sent to 3rd parties as there could be an accidental spillage of sensitive information. Online Content, online tips and other internet connected services baked into applications (whether innocent from the software vendor's perspective or not) can allow for a covert channel to exist where information can travel through.

Impact:

Conversion services will be unavailable.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Do not allow to use Microsoft Conversion Service:

User Configuration\Administrative Templates\Microsoft Office 2016\Tools | Options | General | Service Options...\Online Content\Conversion Service\Conversion Service Options

Default Value:

Disabled. (The conversion service is accessible.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: a09e4d0d4b8ac5a35cb5878be29e77adcecb3bc509833c0babe4211ad382262f