Allow file extensions for OLE embedding
Jump to overview

Policy overview

Key metadata and intent for this policy.

User
Category
Microsoft Office 2016 > Security Settings
Supported on
Windows7

This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.​ This policy setting allows you to specify which file extensions Office won’t block when they are embedded as an OLE package in an Office file by using the Object Packager control. By default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759. Important: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user. If you enable this policy setting, enter the file extensions to allow, separated by semicolons. For example, exe;vbs;js. If you disable or don’t configure this policy setting, the default set of file extensions will be blocked. If you want to block additional file extensions, enable the "Block additional file extensions for OLE embedding" policy setting.

Internal name
L_AllowedExtensions
Policy ID
5000ca628533
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
User
File extensions:
ID L_allowedextensionsole
text
Path
software\policies\microsoft\office\common\security
Value name
allowedextensions
Type
REG_SZ
None
File extensions:
User · Type text
Registry mapping
Path
software\policies\microsoft\office\common\security
Value name
allowedextensions
Type
REG_SZ
DetailsNone