2.2.4.7.2.3.2 Ensure 'Do not open files from the internet zone in Protected View' is set to 'Disabled'

Information

This policy setting determines whether files downloaded from the Internet zone open in Protected View.

The recommended state for this setting is: Disabled.

Rationale:

Allowing users to download files from the Internet zone to open outside of Protected View could allow malicious code to become active on a user's computer or the network.

Impact:

When files open in Protected View, some functionality will be unavailable; users will be unable to edit the file.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\Protected View\Do not open files from the internet zone in Protected View

Default Value:

Disabled. (Files downloaded from the internet zone open in Protected View.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: f4396601a2b1e92e298c8b35b99a796a3475f6917fcf3ed068502d052d57c85f