Disable additional security checks on VBA library references that may refer to unsafe locations on the local machine

Information

This policy setting restricts VBA to checking project library references only against the registry and trusted zones. By default VBA performs additional checks against library paths to prevent loading references from potentially unsafe locations on the local machine as well. It is recommended that this setting remain 0 or unset to allow for the more secure default behavior. Only enable this setting if the default behavior is causing compatibility issues with critical solutions and then only to provide time to migrate the solutions to address the less secure behavior at which point the setting should be turned off again.

Solution

Policy Path: Microsoft Office 2016\Security Settings
Policy Setting Name: Disable additional security checks on VBA library references that may refer to unsafe locations on the local machine

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-for-microsoft-365-apps-for-enterprise-v2112/ba-p/3038172

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 8656a23080044d0dd0e150cc3a77ed599f275057148bbc0a72bc072598c85b1c