V-278359
SV-278359r1130633_rule
Deprecated
CAT II
This rule has been deprecated. Deprecated on 2026-04-07. It is no longer included in the current version of this STIG.
Connected experiences must be disabled.
From: Microsoft Office 365 ProPlus Security Technical Implementation Guide (V3R4)
Description
<VulnDiscussion>These are experiences that use Office content to provide design recommendations, editing suggestions, data insights, and similar features. Examples include PowerPoint Designer and Translator.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
Check Procedure
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Allow the use of connected experiences in Office" is set to "Disabled".
Use the Windows Registry Editor to navigate to the following key:
HKCU\software\policies\Microsoft\office\16.0\common\privacy\
If the value "DisconnectedState" is "REG_DWORD = 2", this is not a finding.
If the registry key does not exist or is not configured properly, this is a finding.
Fix Text
Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Allow the use of connected experiences in Office" to "Disabled".
CCI Reference
CCI-000381- Created
- 2026-03-05 14:03:15
- Last Updated
- 2026-03-05 14:14:58