Back
This checklist helps IT admins and security teams download, test, and apply the DISA STIG controls for Microsoft Office 365 ProPlus across managed endpoints. Follow the steps to stage, validate, audit, and roll out secure Office configurations in your environment.
Progress
0 / 20
- Download STIG SCAP content from DISA — Get the SCAP 1.3 content for Office 365 ProPlus (Ver 3, Rel 7) from DISA.
- Download Standalone XCCDF package — Obtain the XCCDF 1.1.4 standalone file for review and scanning.
- Download DISA-provided GPO package — Save the Group Policy Objects bundle for Office 365 ProPlus from DISA resources.
- Download Intune policy package — Get the Intune policy definitions (latest release) to deploy mobile and managed device settings.
- Download automated SCC/SCCM content — Grab SCC/SCCM automation content to streamline deployment where available.
- Review STIG change history and release notes — Check versions, SHA changes, and recent resource updates before applying controls.
- Inventory Office 365 ProPlus installations — List versions, install channels, and device management state across endpoints.
- Assess your management platforms (Intune, GPO, SCCM) — Decide which platform will enforce each STIG control in your environment.
- Create a test group or pilot collection — Use a small representative set of endpoints/users for staged deployment.
- Apply GPO settings to the test group — Import and enable DISA GPOs in the test OU or policy scope.
- Deploy Intune policies to the test group — Import and assign DISA Intune policies to the pilot device/user group.
- Configure Office update and Click-to-Run settings — Set update channels, enable automatic update, and manage package exclusions as needed.
- Harden Office application security settings — Apply recommended protections to reduce attack surface.
- Disable VBA macros from the internet — Block or restrict macros from untrusted locations and files.
- Enable Protected View for files from the internet — Ensure files from external sources open in Protected View by default.
- Block automatic external content and data connections — Disable automatic download of images, data connections, and external content.
- Test functionality and compatibility in the test group — Validate business workflows and remediate breakages before wider rollout.
- Enable audit logging and monitoring for deployments — Capture changes and events to verify compliance and detect issues.
- Roll out approved settings to production in phases — Expand deployment gradually and monitor for regressions.
- Document applied configurations and store resources — Record settings, resource URLs, SHAs, and change notes for audits.
Your Stats
🏆
0
Completed
📅
—
Last Done
⏱️
—
Last Time
Completion Rate
Items checked per run
⚡
—
Fastest Run
🔥
0
Streak
🚫
—
Most Skipped Step
🔄
0
Resets
📝 My Notes