2.2.4.7.2.6 Ensure 'Block macros from running in Office files from the internet' is set to 'Enabled'

Information

This policy setting allows the blocking of macros from running in Office files that come from the internet.

By enabling this policy setting, macros are blocked from running, even if 'Enable all macros' is selected in the Macro Settings section of the Trust Center. Users will receive a notification that macros are blocked from running.

The exceptions when macros will be allowed to run are:

The Office file is saved to a Trusted Location.

The Office file was previously trusted by the user.

Macros are digitally signed and the matching Trusted Publisher certificate is installed on the device.

The recommended state for this setting is: Enabled.

Rationale:

Windows will mark files downloaded from the internet within an alternative NTFS data stream on the file. Files from untrusted sources can contain malicious payloads embedded in the Macros, including fileless malware, and should be handled with extra care by utilizing additional security controls.

Impact:

This enforces the default behavior and should not cause additional impact.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\Block macros from running in Office files from the internet

Default Value:

Enabled. (Macros are blocked)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1)

Plugin: Windows

Control ID: 62f7c94654dc6b3e20bdb63782777b0c8bd5463323da0374701a7b9d4b84993d