Skip to main content
CUI

STIG Rule - V-278359

V-278359

SV-278359r1130633_rule

Deprecated CAT II

This rule has been deprecated. Deprecated on 2026-04-07. It is no longer included in the current version of this STIG.

Connected experiences must be disabled.

From: Microsoft Office 365 ProPlus Security Technical Implementation Guide (V3R4)

Description

<VulnDiscussion>These are experiences that use Office content to provide design recommendations, editing suggestions, data insights, and similar features. Examples include PowerPoint Designer and Translator.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

Check Procedure

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Allow the use of connected experiences in Office" is set to "Disabled". Use the Windows Registry Editor to navigate to the following key: HKCU\software\policies\Microsoft\office\16.0\common\privacy\ If the value "DisconnectedState" is "REG_DWORD = 2", this is not a finding. If the registry key does not exist or is not configured properly, this is a finding.

Fix Text

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Office 2016 >> Privacy >> Trust Center >> "Allow the use of connected experiences in Office" to "Disabled".

CCI Reference

CCI-000381
Created
2026-03-05 14:03:15
Last Updated
2026-03-05 14:14:58
CUI