2.2.2.1 Ensure 'Do not show data extraction options when opening corrupt workbooks' is set to 'Enabled'

Information

This policy setting controls whether Excel presents users with a list of data extraction options before beginning an Open and Repair operation when users choose to open a corrupt workbook in repair or extract mode.

The recommended state for this setting is: Enabled.

Rationale:

By default, when users choose to open a corrupt workbook with the Open and Repair command, Excel prompts them to choose between repairing or extracting data. A corrupt Excel file may be indicative of malicious tampering. By allowing the automatic handling of corrupt spreadsheets, malicious code may be introduced to the user's computer and the network.

Impact:

This setting will prevent Excel users from choosing how workbooks are recovered, which could increase desktop support requests.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Excel 2016\Data Recovery\Do Not Show Data Extraction Options When Opening Corrupt Workbooks

Default Value:

Disabled. (Excel prompts to user to either extract or repair.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-24

Plugin: Windows

Control ID: db94de9c8ab2e1c40223560784e747fe3d0f834d3c186faf7d8dbb1a3f79b550