Microsoft InfoPath 2013 STIG
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates ✎ 1
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Content changes 1
- V-17471 Medium check All automatic loading from Trusted Locations must be disabled.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO131
- Vuln IDs
-
- V-17187
- Rule IDs
-
- SV-53331r1_rule
Checks: C-47611r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable Trust Bar Notification for unsigned application add-ins" must be "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-46260r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable Trust Bar Notification for unsigned application add-ins" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO133
- Vuln IDs
-
- V-17471
- Rule IDs
-
- SV-53333r2_rule
Checks: C-47612r2_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable all trusted locations" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security\trusted locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-46262r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable all trusted locations" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO157
- Vuln IDs
-
- V-17576
- Rule IDs
-
- SV-53337r1_rule
Checks: C-47614r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Control behavior for Microsoft SharePoint Foundation gradual upgrade" must be set to "Enabled (Block all redirections)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value GradualUpgradeRedirection is REG_DWORD = 2, this is not a finding.
Fix: F-46267r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Control behavior for Microsoft SharePoint Foundation gradual upgrade" to "Enabled (Block all redirections)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO167
- Vuln IDs
-
- V-17580
- Rule IDs
-
- SV-53362r1_rule
Checks: C-47622r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Control behavior when opening InfoPath e-mail forms containing code or script" must be set to "Enabled (Prompt before running)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EMailFormsRunCodeAndScript is REG_DWORD = 1, this is not a finding.
Fix: F-46290r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Control behavior when opening InfoPath e-mail forms containing code or script" to "Enabled (Prompt before running)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO176
- Vuln IDs
-
- V-17611
- Rule IDs
-
- SV-53384r1_rule
Checks: C-47629r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Miscellaneous "Email Forms Beaconing UI" must be set to "Enabled (Always show UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EmailFormsBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-46308r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Miscellaneous "Email Forms Beaconing UI" to "Enabled (Always show UI)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO169
- Vuln IDs
-
- V-17654
- Rule IDs
-
- SV-53378r1_rule
Checks: C-47624r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable dynamic caching of the form template in InfoPath e-mail forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\deployment Criteria: If the value CacheMailXSN is REG_DWORD = 0, this is not a finding.
Fix: F-46302r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable dynamic caching of the form template in InfoPath e-mail forms" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO173
- Vuln IDs
-
- V-17655
- Rule IDs
-
- SV-53383r1_rule
Checks: C-47628r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Full Trust security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableFullTrustEmailForms is REG_DWORD = 0, this is not a finding.
Fix: F-46307r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Full Trust security zone" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO172
- Vuln IDs
-
- V-17656
- Rule IDs
-
- SV-53382r1_rule
Checks: C-47627r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Internet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableInternetEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-46306r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Internet security zone" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO171
- Vuln IDs
-
- V-17657
- Rule IDs
-
- SV-53381r1_rule
Checks: C-47626r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms running in restricted security level" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableRestrictedEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-46305r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms running in restricted security level" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO159
- Vuln IDs
-
- V-17658
- Rule IDs
-
- SV-53353r1_rule
Checks: C-47618r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable fully trusted solutions full access to computer" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value RunFullTrustSolutions is REG_DWORD = 0, this is not a finding.
Fix: F-46280r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable fully trusted solutions full access to computer" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO158
- Vuln IDs
-
- V-17663
- Rule IDs
-
- SV-53340r1_rule
Checks: C-47615r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable opening of solutions from the Internet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value AllowInternetSolutions is REG_DWORD = 0, this is not a finding.
Fix: F-46268r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable opening of solutions from the Internet security zone" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO168
- Vuln IDs
-
- V-17667
- Rule IDs
-
- SV-53366r1_rule
Checks: C-47623r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending form template with e-mail forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\deployment Criteria: If the value MailXSNwithXML is REG_DWORD = 0, this is not a finding.
Fix: F-46292r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending form template with e-mail forms" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO170
- Vuln IDs
-
- V-17668
- Rule IDs
-
- SV-53379r1_rule
Checks: C-47625r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending InfoPath 2003 Forms as e-mail forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath Criteria: If the value DisableInfoPath2003EmailForms is REG_DWORD = 1, this is not a finding.
Fix: F-46303r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending InfoPath 2003 Forms as e-mail forms" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO164
- Vuln IDs
-
- V-17745
- Rule IDs
-
- SV-53357r1_rule
Checks: C-47620r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath" must be set to "Enabled (Always show beaconing UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value InfoPathBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-46284r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath" to "Enabled (Always show beaconing UI)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO165
- Vuln IDs
-
- V-17746
- Rule IDs
-
- SV-53359r1_rule
Checks: C-47621r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath Filler ActiveX" must be set to "Enabled (Always show beaconing UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EditorActiveXBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-46287r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath Filler ActiveX" to "Enabled (Always show beaconing UI)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO156
- Vuln IDs
-
- V-17758
- Rule IDs
-
- SV-53335r2_rule
Checks: C-47613r2_chk
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath Options -> Advanced -> Offline "Offline Mode status" is set to "Enabled (Enabled, InfoPath not in Offline Mode)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\editor\offline Criteria: If the value CachedModeStatus is REG_DWORD = 2, this is not a finding.
Fix: F-46265r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath Options -> Advanced -> Offline "Offline Mode status" to "Enabled (Enabled, InfoPath not in Offline Mode)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO160
- Vuln IDs
-
- V-17764
- Rule IDs
-
- SV-53355r1_rule
Checks: C-47619r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Prevent users from allowing unsafe file types to be attached to forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value DisallowAttachmentCustomization is REG_DWORD = 1, this is not a finding.
Fix: F-46282r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Prevent users from allowing unsafe file types to be attached to forms" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO127
- Vuln IDs
-
- V-26589
- Rule IDs
-
- SV-53328r1_rule
Checks: C-47610r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Require that application add-ins are signed by Trusted Publisher" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value RequireAddinSig is REG_DWORD = 1, this is not a finding.
Fix: F-46258r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Require that application add-ins are signed by Trusted Publisher" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO294
- Vuln IDs
-
- V-26618
- Rule IDs
-
- SV-53385r1_rule
Checks: C-47630r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Intranet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableIntranetEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-46309r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Intranet security zone" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO295
- Vuln IDs
-
- V-26619
- Rule IDs
-
- SV-53389r1_rule
Checks: C-47631r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\outlook\options\mail Criteria: If the value DisableInfopathForms is REG_DWORD = 1, this is not a finding.
Fix: F-46313r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO296
- Vuln IDs
-
- V-26620
- Rule IDs
-
- SV-53392r1_rule
Checks: C-47633r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Disable opening forms with managed code from the Internet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value RunManagedCodeFromInternet is REG_DWORD = 1, this is not a finding.
Fix: F-46316r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Disable opening forms with managed code from the Internet security zone" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO297
- Vuln IDs
-
- V-26621
- Rule IDs
-
- SV-53432r1_rule
Checks: C-47665r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Display a warning that a form is digitally signed" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value SignatureWarning is REG_DWORD = 1, this is not a finding.
Fix: F-46356r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Display a warning that a form is digitally signed" to "Enabled".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO305
- Vuln IDs
-
- V-26625
- Rule IDs
-
- SV-54916r1_rule
Checks: C-48670r1_chk
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2013 -> Global Options -> Customize -> "Disable UI extending from documents and templates" is set to "Enabled" and "Disallow in InfoPath" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\software\policies\Microsoft\office\15.0\common\toolbars\InfoPath Criteria: If the value noextensibilitycustomizationfromdocument is REG_DWORD = 1, this is not a finding.
Fix: F-47784r2_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2013 -> Global Options -> Customize -> "Disable UI extending from documents and templates" to "Enabled". Select the policy option for "Disallow in InfoPath".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO309
- Vuln IDs
-
- V-26697
- Rule IDs
-
- SV-53452r1_rule
Checks: C-47667r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2013 (Machine) -> Security "InfoPath APTCA Assembly Allowable List Enforcement" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\15.0\InfoPath\security Criteria: If the value APTCA_AllowList is REG_DWORD = 1, this is not a finding.
Fix: F-46378r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2013 (Machine) -> Security "InfoPath APTCA Assembly Allowable List Enforcement" to "Enabled".