Policy

Block additional file extensions for OLE embedding

This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.​ This policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control. By default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759. Important: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user. If you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb. If you disable or don’t configure this policy setting, the default set of file extensions will be blocked. If you want to allow certain file extensions, enable the "Allow file extensions for OLE embedding" policy setting. Extensions added to this policy setting will take precedence over extensions in "Allow file extensions for OLE embedding"

Policy
Pack Microsoft Office
Category Microsoft Office 2016 / Security Settings
Policy ID 59737771da51
Internal name L_BlockedExtensions

Registry

Copy registry mappings

HKCU\software\policies\microsoft\office\common\security\blockedextensions

Policy notes

This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.​ This policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control. By default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759. Important: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user. If you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb. If you disable or don’t configure this policy setting, the default set of file extensions will be blocked. If you want to allow certain file extensions, enable the "Allow file extensions for OLE embedding" policy setting. Extensions added to this policy setting will take precedence over extensions in "Allow file extensions for OLE embedding"

Related policies