Information
For each SharePoint web application, the platform should be configured to prevent users
from accessing the Online Web Part Gallery.
Rationale:
Web parts are reusable components that render sections of a SharePoint Web page. The
available web parts are displayed in the Web Parts Gallery, which is a collection of web
parts located on the internet. The Online Gallery could contain Web Parts from unknown
third parties, which could increase the risk of a malicious code execution attack. Preventing
users from accessing the Online Web Part Gallery decreases the system's attack surface.
Solution
Login to Central Administration.
Navigate to Security > Manage Web Part Security
For each web application in the web application section, perform the following:
. Select the correct web application in the web application section.
. Select the 'Prevents users from accessing the Online Web Part Gallery, and helps to
improve security and performance' option in the Online Web Part Gallery section.