Information
This policy setting controls whether trusted locations can be defined by users, the Office Customization Tool (OCT), and Intune profiles, or if they must be defined by Intune profiles alone.
The recommended state for this setting is: Disabled
When files are opened from trusted locations, all the content in the files is enabled and active. Users are not notified about any potential risks that might be contained in the files, such as unsigned macros, ActiveX controls, or links to content on the Internet.
By default, users can specify any location as a trusted location, and a computer can have a combination of user-created, OCT-created, and Group Policy-created trusted locations.
Solution
To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :
Microsoft Office 2016\Security Settings\Trust Center\Allow Mix of Policy and User Locations
Impact:
Disabling this setting will cause some disruption for users who have defined their own trusted locations in the Trust Center. Applications will treat such locations like any other untrusted locations, which means that users will see Message Bar warnings about active content such as ActiveX controls and VBA macros when they open files, and they will have to choose whether to enable controls and macros or leave them disabled.