2.6.6.6.2.2.1 Ensure 'Do not open files from the Internet zone in Protected View' is set to 'Disabled'

Information

This policy setting determines whether files downloaded from the Internet zone open in Protected View.

The recommended state for this setting is: Disabled.

Rationale:

Allowing users to download files from the Internet zone to open outside of Protected View could allow malicious code to become active on a user's computer or the network.

Impact:

When files open in Protected View, some functionality will be unavailable and productivity in your organization could be affected. When this is undesirable, users will have to add sites to their trusted sites list, thus allowing the files to be opened in normal view with all functionality available.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled.

User Configuration\Administrative Templates\Microsoft PowerPoint 2016\PowerPoint Options\Security\Trust Center\Protected View\Do not open files from the Internet zone in Protected View

Default Value:

Disabled. (Files downloaded from the Internet zone open in Protected View.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 12381b09fbbda652757a288636be4fa7e75f84bf17b8641e9ea3d2b37340ad75