1.4.5.1.1 Ensure 'Internet and Network Paths as Hyperlinks' is set to Disabled

Information

This policy setting determines whether Excel automatically creates hyperlinks when users enter URL or UNC path information. The recommended state for this setting is: Disabled. By default, when users type a string of characters that Excel recognizes as a Uniform Resource Locator (URL) or Uniform Naming Convention (UNC) path to a resource on the Internet or a local network, Excel will transform it into a hyperlink. Clicking the hyperlink opens it in the configured default Web browser or the appropriate application. This functionality can enable users to accidentally create links to dangerous or restricted resources, which could create a security risk.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Disabled. User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Proofing\Autocorrect Options\Internet and Network Paths as Hyperlinks Impact: If this setting is disabled, Excel users will still be able to create new hyperlinks manually, so it is unlikely to cause significant disruptions for most users.

See Also

https://workbench.cisecurity.org/files/569

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: beaf249b136e69813ceae73796d9784025ef9838eda9c00e8babc71865d8b47d