2.2.4.7.2.2.13 (L1) Ensure 'Set default file block behavior' is set to 'Enabled: Blocked files are not opened'

Information

This policy setting determines if users can open, view, or edit Word files that are by default blocked by Microsoft Office.

The recommended state for this setting is: Enabled: Blocked files are not opened

By default, users can open, view, or edit many file types in Word. Some file types are safer than others, as some could allow malicious code to be executed on a user computer or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Blocked files are not opened

Microsoft Excel 2016\Excel Options\Security\Trust Center\File Block Settings\Set Default File Block Behavior

Impact:

Enabling this setting prevents users from opening, viewing, or editing certain types of files in Word. Productivity could be affected if users who require access to any of these file types cannot access them.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: a56ba3c0b9215b0ac8dfb9d3f8ac6043174a32ffccf2961d7943738aa56e61fc