2.2.4.7.2.1.1 (L1) Ensure 'Always prevent untrusted Microsoft Query files from opening' is set to 'Enabled'

Information

This policy setting controls whether Microsoft Query files (.iqy, oqy, .dqy, and .rqy) in an untrusted location are prevented from opening.

Using Microsoft Query, users can connect to external data sources, select data from those external sources, import that data into worksheets, and refresh it to keep worksheet data synchronized with the data in the external sources.

Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.

The recommended state for this setting is: Enabled

Microsoft Query files that have been tampered with and placed in an untrusted location could allow an attacker to affect the confidentiality and integrity of a spreadsheet.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled

Microsoft Excel 2016\Excel Options\Security\Trust Center\External Content\Always prevent untrusted Microsoft Query files from opening

Impact:

Microsoft Query files in an untrusted location are prevented from opening. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > External Content.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(1)

Plugin: Windows

Control ID: 5ca920d9ef97950970e9dea81ab1c13103c7cc83de749cdfc504e6a1dd27dab7