Information
This policy setting controls how Excel will warn users when WEBSERVICE functions are present.
When selecting the option 'Disable all with notification' the application displays the Trust Bar for all WEBSERVICE functions. This option enforces the default configuration in Office.
The recommended state for this setting is: Enabled: Disable all without notification.
Rationale:
WEBSERVICE functions can be used alongside of formula injection to cause users of an Excel spreadsheet to unknowingly connect to systems controlled by bad actors, or even exfiltrate data.
Impact:
Users will not be notified when a WEBSERVICE function is disabled.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Disable all without notification.
User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\WEBSERVICE Function Notification Settings
Default Value:
Disabled. (WEBSERVICE functions are disabled, but can be enabled via the Trust Bar by an end user.)