1.4.7.2.2.3 Ensure 'Do Not Open Files in Unsafe Locations in Protected View' is set to Disabled

Information

This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the 'Downloaded Program Files' and 'Temporary Internet Files' folders are considered unsafe locations. The recommended state for this setting is: Disabled. Enabling this setting allows users to open files located in unsafe locations that do not require Protected View. As a result, malicious code could become active on user computers or the network.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Disabled. User Configuration\Administrative Templates\Microsoft Excel 2013\Excel Options\Security\Trust Center\Protected View\Do Not Open Files in Unsafe Locations in Protected View Impact: The Downloaded Program Files folder and the Temporary Internet Files folder are considered unsafe locations. You may specify additional unsafe locations. Some functionality is not available when files are opened in Protected View. In such cases, users must move the files from unsafe locations to save locations in order to access them with full functionality

See Also

https://workbench.cisecurity.org/files/568

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 25048242cab81f9a908d9e23d9a0ba6c1bf97291435ab743cd672b6df3355b9e