Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 1)
19 items · Security · Medium difficulty · 1 hour
Harden Adobe Acrobat Reader DC for managed Windows environments using DISA STIG steps.
-
Verify Adobe Acrobat Reader DC product track
Confirm Continuous vs Classic before applying STIG settings.
-
Check installation path for Continuous track (C:Program Files (x86)AdobeAcrobat Reader DC)
Continuous track defaults to this folder.
-
Check Programs and Features entry to confirm 'Adobe Acrobat Reader DC' (Continuous) or 'Adobe Acrobat Reader MUI' (Classic)
Use Programs and Features if path is ambiguous.
-
Install or update to the approved Continuous track version
Apply the organization's approved Reader build before policy changes.
-
Download DISA SCAP, XCCDF, GPO, Intune and SCC resources
Obtain the latest STIG content, GPO and Intune packages from DISA.
-
Apply DISA-provided GPO files to Active Directory
Import and link the GPO to target OUs.
-
Import Intune policies into Microsoft Intune and assign to device groups
Upload and assign Intune policy packs for Reader DC.
-
Configure silent automatic updates for the Continuous track
Set updates to silent so security fixes apply promptly.
-
Disable Adobe Document Cloud and online services features
Block cloud integrations if not authorized by policy.
-
Disable JavaScript execution in Acrobat Reader
Turn off JavaScript to reduce attack surface.
-
Enable Protected View/Protected Mode and configure enhanced security
Ensure sandboxing and enhanced protection are enforced.
-
Restrict or remove unnecessary plugins and browser extensions
Disable third-party plug-ins not required by users.
-
Enforce browser PDF handling to use managed system viewer settings
Prevent unmanaged or legacy viewers from handling PDFs.
-
Verify policy deployment and compliance on target hosts
Confirm settings applied and report noncompliance.
-
Run gpresult /h or use GPO reporting to confirm GPO settings on a test host
Generate a report showing applied GPO settings.
-
Check Intune device configuration status and compliance in the Intune portal
Review assignment and deployment success/failures.
-
Enable auditing of Acrobat Reader installations and updates
Log installs/updates for incident response and tracking.
-
Document exceptions, test impacts, and a phased roll-out plan
Test in representative environments before wide deployment.
-
Subscribe to DISA STIG updates, SHA changes and resource feeds
Stay current with DISA resource and checksum updates.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.