2.3.37.3.1 Ensure 'Open Office documents as read/write while browsing' is set to 'Disabled'

Information

This policy setting controls whether users can edit and save Office documents on Web servers that they have opened using Internet Explorer.

The recommended state for this setting is: Disabled.

Rationale:

By default, when users browse to an Office document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode. However, if the default configuration is changed, the document is opened as read/write. Users could potentially make changes to documents and resave them in situations where the Web server security is not configured to prevent such changes.

Impact:

This setting enforces the Office default configuration and therefore should have minimal impact on users.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Tools | Options | General | Web Options...\Files\Open Office Documents as Read/Write While Browsing

Default Value:

Disabled.

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18

Plugin: Windows

Control ID: aabfb075ff8e1500b7efdd1a381e2c1dbc47097186bdd8902763acd14e231ac5