2.11.8.7.2.2.2 Ensure 'Do not open files in unsafe locations in Protected View' is set to 'Disabled'

Information

This policy setting determines if files located in unsafe locations will open in Protected View.

The recommended state for this setting is: Disabled.

Rationale:

Opening files located in unsafe locations that do not require Protected View could lead to malicious code executing on a user's computer or the network.

Note: If a specified unsafe location(s) is not configured, the 'Downloaded Program Files' and 'Temporary Internet Files' folders are considered unsafe locations.

Impact:

Some functionality is not available when files are opened in Protected View. In such cases, users must move the files from unsafe locations to safe locations in order to access them with full functionality.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled.

User Configuration\Administrative Templates\Microsoft Word 2016\Word Options\Security\Trust Center\Protected View\Do Not Open Files in Unsafe Locations in Protected View

Default Value:

Disabled. (Files located in unsafe locations open in Protected View.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: d04ecabe26a149ecff71b97c96263202e6c25582755cc335482fccdaa46b7b58