UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Disable User Entries to Server List - Outlook


Overview

Finding ID Version Rule ID IA Controls Severity
V-17944 DTOO286 - Outlook SV-19435r1_rule ECSC-1 Medium
Description
If users are able to manually enter the addresses of servers that are not approved by the organization, they could use servers that do not meet your organization's information security requirements, which could cause sensitive information to be at risk. By default, when users create a meeting workspace, they can choose a server from a default list provided by administrators or manually enter the address of a server that is not listed.
STIG Date
Microsoft Outlook 2007 2014-10-03

Details

Check Text ( C-20428r1_chk )
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Meeting Workspace “Disable user entries to server list” will be set to “Enabled (Publish default, disallow others)”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\12.0\Meetings\Profile

Criteria: If the value ServerUI is REG_DWORD = 2, this is not a finding.
Fix Text (F-18394r1_fix)
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Meeting Workspace “Disable user entries to server list” will be set to “Enabled (Publish default, disallow others)”.