2.11.8.7.2.2.4 (L1) Ensure 'Set document behavior if file validation fails' is set to 'Unchecked: Do not allow edit`

Information

This policy setting controls how Office handles documents when they fail file validation.

Office File Validation is a feature that performs security checks on files. If Office File Validation detects a problem with a file, the file cannot be opened.

The recommended state for this setting is: Unchecked: Do not allow edit (false)

Files that have failed file validation outside of Protected View could allow malicious code to execute on the system or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Unchecked: Do not allow edit (false)

Microsoft Word 2016\Word Options\Security\Trust Center\Protected View\Document Behavior if File Validation Fails

Impact:

Files that are blocked by the validation fail rule will not open on a user's computer.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 89e54275c2cd763bcc0224713dd53109d50abb964c100d8b9534b0bef4effd3c