SOLVED

"Block Flash activation in Office documents" Security Recommendation

%3CLINGO-SUB%20id%3D%22lingo-sub-634398%22%20slang%3D%22en-US%22%3E%22Block%20Flash%20activation%20in%20Office%20documents%22%20Security%20Recommendation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-634398%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20seems%20like%20the%20security%20recommendation%20for%20the%20%22Block%20Flash%20activation%20in%20Office%20documents%22%20actually%20does%20the%20opposite%20of%20what%20is%20intended%20and%20overrides%20the%20disabled-by-default%20ability%20to%20load%20Flash%20components%20in%20Office%20documents.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20guidance%20states%20the%20following%3A%3C%2FP%3E%3CPRE%3ERemediation%20options%3CBR%20%2F%3E%3CBR%20%2F%3ESet%20the%20following%20registry%20value%3A%3CBR%20%2F%3EHKLM%5CSOFTWARE%5CMicrosoft%5COffice%5C16.0%5CCommon%5CCOM%20Compatibility%5C%7BD27CDB6E-AE6D-11CF-96B8-444553540000%7D%5Cactivationfilteroverride%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20the%20following%20value%3A%201%3C%2FPRE%3E%3CP%3EAccording%20to%20this%20Microsoft%20article%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2Fflash-silverlight-and-shockwave-controls-blocked-in-microsoft-office-55738f12-a01d-420e-a533-7cef1ff6aeb1%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%5B%20Flash%2C%20Silverlight%2C%20and%20Shockwave%20controls%20blocked%20in%20Microsoft%20Office%20%5D%3C%2FA%3E%2C%20this%20is%20exactly%20what%20you'd%20do%20if%20you%20wanted%20to%20override%20the%20already%20disabled%20component.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-729082%22%20slang%3D%22en-US%22%3ERe%3A%20%22Block%20Flash%20activation%20in%20Office%20documents%22%20Security%20Recommendation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-729082%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131751%22%20target%3D%22_blank%22%3E%40Philip%20Kluss%3C%2FA%3E%20this%20looks%20like%20a%20question%20for%20the%20office%20forum%2C%20not%20Microsoft%20Defender%20ATP%20or%20am%20I%20mistaken%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-742563%22%20slang%3D%22en-US%22%3ERe%3A%20%22Block%20Flash%20activation%20in%20Office%20documents%22%20Security%20Recommendation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-742563%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F63582%22%20target%3D%22_blank%22%3E%40Heike%20Ritter%3C%2FA%3Eit%20is%20a%20security%20recommendation%20in%20Windows%20Defender%20ATP.%26nbsp%3B%20I%20would%20say%20it%20does%20belong%20here.%20%26nbsp%3B%20Affects%20your%20security%20score.%26nbsp%3B%20If%20it%20is%20enabled%20incorrectly%20we%20all%20need%20to%20know.%3C%2FP%3E%3CBLOCKQUOTE%3E%3CHR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F63582%22%20target%3D%22_blank%22%3E%40Heike%20Ritter%3C%2FA%3E%26nbsp%3Bwrote%3A%3CBR%20%2F%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131751%22%20target%3D%22_blank%22%3E%40Philip%20Kluss%3C%2FA%3Ethis%20looks%20like%20a%20question%20for%20the%20office%20forum%2C%20not%20Microsoft%20Defender%20ATP%20or%20am%20I%20mistaken%3F%3C%2FP%3E%3CHR%20%2F%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-745163%22%20slang%3D%22en-US%22%3ERe%3A%20%22Block%20Flash%20activation%20in%20Office%20documents%22%20Security%20Recommendation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-745163%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131751%22%20target%3D%22_blank%22%3E%40Philip%20Kluss%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThank%20you%20for%20your%20message.%3C%2FP%3E%0A%3CP%3EWe%20had%20a%20mistake%20in%20checking%20the%20expected%20value.%20%3CBR%20%2F%3Ethe%20problem%20already%20solved%20and%20you%20should%20see%20the%20correct%20recommendation%20in%20the%20portal.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3EHaim%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

It seems like the security recommendation for the "Block Flash activation in Office documents" actually does the opposite of what is intended and overrides the disabled-by-default ability to load Flash components in Office documents.

 

The guidance states the following:

Remediation options

Set the following registry value:
HKLM\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}\activationfilteroverride

To the following value: 1

According to this Microsoft article [ Flash, Silverlight, and Shockwave controls blocked in Microsoft Office ], this is exactly what you'd do if you wanted to override the already disabled component.

3 Replies

@Philip Kluss this looks like a question for the office forum, not Microsoft Defender ATP or am I mistaken?

@Heike Ritterit is a security recommendation in Windows Defender ATP.  I would say it does belong here.   Affects your security score.  If it is enabled incorrectly we all need to know.


@Heike Ritter wrote:

@Philip Klussthis looks like a question for the office forum, not Microsoft Defender ATP or am I mistaken?


 

best response confirmed by Philip Kluss (Contributor)
Solution

Hi @Philip Kluss,

 

Thank you for your message.

We had a mistake in checking the expected value.
the problem already solved and you should see the correct recommendation in the portal.

 

Thanks,

Haim