Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” must be “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable all trusted locations” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security\trusted locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable all trusted locations” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Control behavior for Microsoft SharePoint Foundation gradual upgrade” must be set to “Enabled (Block all redirections)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value GradualUpgradeRedirection is REG_DWORD = 2, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Control behavior for Microsoft SharePoint Foundation gradual upgrade” to “Enabled (Block all redirections)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Control behavior when opening InfoPath e-mail forms containing code or script” must be set to “Enabled (Prompt before running)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value EMailFormsRunCodeAndScript is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Control behavior when opening InfoPath e-mail forms containing code or script” to “Enabled (Prompt before running)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Miscellaneous “Email Forms Beaconing UI” must be set to “Enabled (Always show UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EmailFormsBeaconingUI is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Miscellaneous “Email Forms Beaconing UI” to “Enabled (Always show UI)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable dynamic caching of the form template in InfoPath e-mail forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\deployment Criteria: If the value CacheMailXSN is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable dynamic caching of the form template in InfoPath e-mail forms” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Full Trust security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableFullTrustEmailForms is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Full Trust security zone” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Internet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableInternetEMailForms is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Internet security zone” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms running in restricted security level” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableRestrictedEMailForms is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms running in restricted security level” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable fully trusted solutions full access to computer” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value RunFullTrustSolutions is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable fully trusted solutions full access to computer” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable opening of solutions from the Internet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value AllowInternetSolutions is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable opening of solutions from the Internet security zone” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending form template with e-mail forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\deployment Criteria: If the value MailXSNwithXML is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending form template with e-mail forms” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath Criteria: If the value DisableInfoPath2003EmailForms is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath” must be set to “Enabled (Always show beaconing UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value InfoPathBeaconingUI is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath” to “Enabled (Always show beaconing UI)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath Filler ActiveX" must be set to “Enabled (Always show beaconing UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EditorActiveXBeaconingUI is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath Filler ActiveX" to “Enabled (Always show beaconing UI)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath Options -> Advanced -> Offline “Offline Mode status” must be set to “Enabled (Enabled, InfoPath not in Offline Mode)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\editor\offline Criteria: If the value CachedModeStatus is REG_DWORD = 2, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath Options -> Advanced -> Offline “Offline Mode status” to “Enabled (Enabled, InfoPath not in Offline Mode)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Prevent users from allowing unsafe file types to be attached to forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value DisallowAttachmentCustomization is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Prevent users from allowing unsafe file types to be attached to forms” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Require that application add-ins are signed by Trusted Publisher” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value RequireAddinSig is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Require that application add-ins are signed by Trusted Publisher” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Turn off Data Execution Prevention” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableDEP is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Turn off Data Execution Prevention” to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Intranet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableIntranetEMailForms is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Intranet security zone” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\outlook\options\mail Criteria: If the value DisableInfopathForms is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Disable opening forms with managed code from the Internet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value RunManagedCodeFromInternet is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Disable opening forms with managed code from the Internet security zone” to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Display a warning that a form is digitally signed” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value SignatureWarning is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Display a warning that a form is digitally signed” to “Enabled”.
The policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2010 (Machine) -> Security “InfoPath APTCA Assembly Allowable List Enforcement” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\14.0\infopath\security Criteria: If the value APTCA_AllowList is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2010 (Machine) -> Security “InfoPath APTCA Assembly Allowable List Enforcement” to “Enabled”.