STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to Microsoft Internet Explorer 11 Security Technical Implementation Guide

V-223050

CAT II (Medium)

Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Internet Zone.

Rule ID

SV-223050r960963_rule

STIG

Microsoft Internet Explorer 11 Security Technical Implementation Guide

Version

V2R7

CCIs

CCI-000381

Discussion

This policy setting determines whether users can run the Tabular Data Control (TDC) ActiveX control, based on security zone. By default, the TDC ActiveX Control is disabled in the Internet and Restricted Sites security zones. If you enable this policy setting, users will not be able to run the TDC ActiveX control from all sites in the specified zone.

Check Content

In the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Security Page >> Internet Zone, verify "Allow only approved domains to use the TDC ActiveX control" is “Enabled”. 

In the Options window, verify the “Only allow approved domains to use the TDC ActiveX control" drop-down box is set to “Enable”. 

Procedure: Use the Windows Registry Editor to navigate to the following key: 

HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 

Criteria: 

If the value "120c" is REG_DWORD = “3”, this is not a finding.

Fix Text

In the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Pane >> Security Page >> Internet Zone, set the "Allow only approved domains to use the TDC ActiveX control" to “Enabled”. 

In the Options window, select "Enable" from the “Only allow approved domains to use the TDC ActiveX control" drop-down box.