DTOO234 - ActiveX One-Off forms must be configured.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2016 -> Security 'Allow Active X One Off Forms' to 'Enabled: Load only Outlook Controls'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_MS_Outlook_2016_V1R2_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, CCI|CCI-001170, Rule-ID|SV-85773r1_rule, STIG-ID|DTOO234, Vuln-ID|V-71149

Plugin: Windows

Control ID: 551502f8f2789c46d4b545b69aa87252f1652f858c521e0847415800bfc18adf