Information
This policy setting determines whether users can open, view, edit, or save Web pages and Excel 2003 XML spreadsheets.
Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the 'default file block behavior' key.
Note: Use Open Policy action is defined by the Set default file block behavior group policy setting which is included in this benchmark.
The recommended state for this setting is: Enabled: Open/Save blocked, use open policy.
Rationale:
Using legacy file formats could allow malicious code to become active on a user's computer or the network.
Impact:
Users will not be able to open, save, or view Web pages and Excel 2003 XML spreadsheets. In addition, the following file types will open in Protected View: .mht .mhtml .htm .html .xml .xlmss
While in OneNote using the function 'Convert a Table to Excel' may cause OneNote to freeze until a dialogue box is confirmed.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Open/Save blocked, use open policy.
User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\File Block Settings\Web Pages and Excel 2003 XML Spreadsheets
Default Value:
Disabled. (The file type will not be blocked.)