Policy
Block additional file extensions for OLE embedding
Microsoft Office 5532.1000
Policy overview
Key metadata and intent for this policy.
This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio. This policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control. By default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759. Important: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user. If you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb. If you disable or don’t configure this policy setting, the default set of file extensions will be blocked. If you want to allow certain file extensions, enable the "Allow file extensions for OLE embedding" policy setting. Extensions added to this policy setting will take precedence over extensions in "Allow file extensions for OLE embedding"
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
File extensions: ID L_blockedextensionsole | text | HKCU\software\policies\microsoft\office\common\security\blockedextensions Type REG_SZ | None |
Other policies in this category
Explore related policies at the same level.
- UserActiveX Control InitializationWindows7
- UserAllow Basic Authentication prompts from network proxiesWindows7
- UserAllow file extensions for OLE embeddingWindows7
- UserAllow root or intermediate certificates as VBA trusted publishersWindows 10
- UserAllow specified hosts to show Basic Authentication prompts to Office appsWindows7
- UserAllow VBA to load typelib references by path from untrusted intranet locationsWindows 10
- UserAutomation SecurityWindows7
- UserBlock all internet macros (ignore trusted locations or publishers)Windows 10
- UserBlock Insecure ProtocolsWindows7
- UserBlock loading of COM/VSTO add-ins registered in HKCUWindows 10
- UserBlock OLE GraphWindows7
- UserBlock OrgChartWindows7