2.11.8.7.2.2.1 (L1) Ensure 'Do not open files from the internet zone in Protected View' is set to 'Disabled'

Information

This policy setting determines whether files downloaded from the Internet zone open in Protected View.

The recommended state for this setting is: Disabled

Allowing users to download files from the Internet zone to open outside of Protected View could allow malicious code to become active on a user's computer or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled

Microsoft Word 2016\Word Options\Security\Trust Center\Protected View\Do Not Open Files From The Internet Zone in Protected View

Impact:

When files open in Protected View, some functionality will be unavailable. Users will be unable to edit the file.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 6164ac0a188f02f2490aa2b9ba92be02126f23d34f981663059d510969cb73bc