2.2.4.7.2.3.5 Ensure 'Set document behavior if file validation fails' is set to 'Unchecked: Do not allow edit'

Information

This policy setting controls how Office handles documents when they fail file validation.

Office File Validation is a feature that performs security checks on files. If Office File Validation detects a problem with a file, the file cannot be opened.

The recommended state for this setting is: Unchecked: Do not allow edit.

Rationale:

Files that have failed file validation outside of Protected View could allow malicious code to execute on the system or the network.

Impact:

Files that are blocked by the validation fail rule will not open on a user's computer.

Solution

To establish the recommended configuration via GP, set the following UI path to Unchecked: Do not allow edit.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\Protected View\Set document behavior if file validation fails

Default Value:

Enabled. (Open in Protected View (Unchecked).)

Additional Information:

If this policy setting is disabled, Office follows the 'Open files in Protected View and disallow edit' behavior.

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 7eb71dfd1f32de32056bc4c7bd30d9ad506bf6ee6d8957a65e3b777a09e3b4b2