UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The ability to sign into Office365 must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-40862 DTOO405 SV-53194r3_rule Medium
Description
Office 2013 can be configured to prompt users for credentials to Office365 using either their Microsoft Account or the user ID assigned by an organization for accessing Office 365. Access to Office 365 will not be permitted and only locally installed and configured Office installations will be used.
STIG Date
Microsoft Office System 2013 STIG 2019-03-21

Details

Check Text ( C-47500r4_chk )
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2013 >> Miscellaneous >> "Block signing into Office" is set to "Enabled: org ID only".

Use the Windows Registry Editor to navigate to the following HKCU\Software\Policies\Microsoft\Office\15.0\common\signin

If the value “signinoptions” is REG_DWORD = 2 for every user profile hive, this is not a finding.
Fix Text (F-46120r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2013 -> Miscellaneous -> "Block signing into Office" to "Enabled: org ID only".