2.6.6.6.2.3.1 (L1) Ensure 'Allow Trusted Locations on the network' is set to 'Disabled'

Information

This policy setting controls whether trusted locations on the network can be used. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe by the application opening the file.

The recommended state for this setting is: Disabled

Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm the user's computers or data.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled

Microsoft PowerPoint 2016\PowerPoint Options\Security\Trust Center\Trusted Locations\Allow Trusted Locations on the network

Impact:

Disabling this setting will cause disruption for users who add network locations to the Trusted Locations list. These custom locations added by users are ignored but not removed. Trusted locations added in Group Policy that specify a network location are also ignored.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: d2b4b52d9cc9a4381180a1f108ca73404fe0f64dfb040c0d924a660e6f22eb0e