1. Home
  2. Security Hardening
  3. DISA STIG Microsoft Outlook 2013 V1R13
  4. DTOO217 – Publishing to a Web Distributed and Authoring (DAV) server must be prevented.

DTOO217 – Publishing to a Web Distributed and Authoring (DAV) server must be prevented.

Details

Outlook users can share their calendars with others by publishing them to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Unlike the Microsoft Office Online Calendar Sharing Service, which allows users to manage other people’s access to their calendars, DAV access restrictions can only be accomplished through server and folder permissions, and might require the assistance of the server administrator to set up and maintain. If these permissions are not managed properly, unauthorized individuals could access sensitive information.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Outlook Options -> Preferences -> Calendar Options -> Office.com Sharing Service ‘Prevent publishing to a DAV server’ to ‘Enabled’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles