2.6.6.6.2.1.2 (L1) Ensure 'Set default file block behavior' to 'Enabled: Blocked files are not opened'

Information

This policy setting determines if users can open, view, or edit Word files that are by default blocked by Microsoft Office.

The recommended state for this setting is: Enabled: Blocked files are not opened

By default, users can open, view, or edit a large number of file types in Word. Some file types are safer than others, as some could allow malicious code to execute on a user computer or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Blocked files are not opened :

Microsoft PowerPoint 2016\PowerPoint Options\Security\Trust Center\File Block Settings\Set Default File Block Behavior

Impact:

Enabling this setting prevents users from opening, viewing, or editing certain types of files in Word. Productivity could be affected if users who require access to any of these file types cannot access them.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: 269f758a199624746572786b06ea4592c05c5c09a3a8f20d2a4230295f7e9a9f