2.2.4.7.4 Ensure 'Scan encrypted macros in Excel Open XML workbooks' is set to 'Enabled: Scan encrypted macros (default)'

Information

This policy setting controls whether encrypted macros in Open XML documents are required to be scanned with anti-virus software before being opened.

The recommended state for this setting is: Enabled: Scan encrypted macros (default).

Rationale:

When an Office Open XML document is rights-managed or password protected, macros that are embedded in the document are encrypted along with the rest of the workbook's contents. Macros can contain malicious code which could cause a virus to load undetected and lead to data loss or reduced application functionality.

Impact:

None - this is the default behavior.

By default, encrypted macros will be disabled unless they are scanned by antivirus software immediately before being loaded.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Scan encrypted macros (default).

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Scan Encrypted Macros in Excel Open XML Workbooks

Default Value:

Scan encrypted macros. (Disabled and Not Configured are functionally equivalent.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3

Plugin: Windows

Control ID: 911473bb2b2d47b64b1ece3e779e4e736e1472bb6fae5ab58a380dc0f16a9f74