1.1.4.1.13 Ensure 'Saved from URL' is set to 'Enabled'

Information

This setting controls whether Internet Explorer evaluates URLs passed to it by Office applications for Mark of the Web (MOTW) comments.

The recommended state for this setting is: Enabled: groove.exe, excel.exe, mspub.exe, powerpnt.exe, pptview.exe, visio.exe, winproj.exe, winword.exe, outlook.exe, spDesign.exe, exprwd.exe, msaccess.exe, onent.exe, mse7.exe.

Rationale:

Typically, when Internet Explorer loads a Web page from a UNC share that contains a Mark of the Web (MOTW) comment indicating the page was saved from a site on the Internet, Internet Explorer runs the page in the Internet security zone instead of the less restrictive Local Intranet security zone. This functionality can be controlled separately for instances of Internet Explorer spawned by Office applications (for example, if a user clicks a link in an Office document or selects a menu option that loads a Web page). If Internet Explorer does not evaluate the page for a MOTW, potentially dangerous code could be allowed to run.

Impact:

Enabling this setting can cause some Web pages saved on UNC shares to run in a more restrictive security zone when opened from Office applications than they would if the setting were disabled or not configured. However, a page with a MOTW indicating it was saved from an Internet site is presumed to have been designed to run in the Internet zone in the first place, so most users should not experience significant usability issues.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Check all applications:

Computer Configuration\Administrative Templates\Microsoft Office 2016 (Machine)\Security Settings\IE Security\Saved from URL

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4)

Plugin: Windows

Control ID: c735681a0a1d7a56f853ee110aa983f0bbbb55a0efaa43412b9660b638915d73