2.6.6.6.2.2.3 Ensure 'Set document behavior if file validation fails' is set to 'Enabled: Open in Protected View'

Information

This policy setting controls how Office handles documents when they fail file validation.

Office File Validation is a feature that performs security checks on files. If Office File Validation detects a problem with a file, the file cannot be opened.

The recommended state for this setting is: Enabled: Open in Protected View.

Rationale:

Files that have failed file validation outside of Protected View could allow malicious code to execute on the system or the network.

Impact:

Files that are blocked by the validation fail rule will not open on a user's computer.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Open in Protected View.

User Configuration\Administrative Templates\Microsoft PowerPoint 2016\PowerPoint Options\Security\Trust Center\Protected View\Set Document Behavior if File Validation Fails

Default Value:

Enabled: Open in Protected View (Checked allow edit)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: d0ae9f10c9f742f16c95366c5f41a1ab133834f3ff562b235179ae67c8530efb