2.2.4.7.2.1.1 Ensure 'Always prevent untrusted Microsoft Query files from opening' is set to 'Enabled'

Information

This policy setting controls whether Microsoft Query files (.iqy, oqy, .dqy, and .rqy) in an untrusted location are prevented from opening.

Using Microsoft Query, users can connect to external data sources, select data from those external sources, import that data into worksheets, and refresh it to keep worksheet data synchronized with the data in the external sources.

Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.

The recommended state for this setting is: Enabled.

Rationale:

Microsoft Query files that have been tampered with and placed in an untrusted location could allow an attacker to affect the confidentiality and integrity of a spreadsheet.

Impact:

Microsoft Query files in an untrusted location are prevented from opening. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > External Content.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\External Content\Always prevent untrusted Microsoft Query files from opening

Default Value:

Disabled. (Query files in an untrusted location are not prevented from opening.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(1)

Plugin: Windows

Control ID: 9b6afd81683ea5fbb9f22450e931213a92220381580c4a07ee5d14420e0c1a9b