高安全环境下Normal.dotm及C盘安全策略相关Word信任中心问题
C:\ Drive Security Policy Gaps & Word Template Behavior Breakdown
Hey there, let's break down the issues with your company's C:\ drive security rules and the related Microsoft Word quirks you've noticed:
Core Security Policy
Our company has a strict rule for the C:\ drive:
- No user data is allowed to be saved locally on this drive
- All user files must be stored exclusively on network drives
Identified Policy Vulnerabilities
This policy has a couple of critical loopholes that lead to unintended writes to the C:\ drive:
- Temporary file storage: Most applications automatically generate and store temporary files in default C:\ locations (like
C:\Windows\Tempor user-specific temp folders) without any user input—these often slip past the policy's restrictions - Normal.dotm/Normal.dotx template writes: Microsoft Word depends on these template files to maintain default formatting and settings. It will automatically create or update these files in the user's local AppData folder on C:, completely bypassing the requirement to use network drives
Word Trust Center & Hidden Template Path Details
When you check Word's Trust Center under the User Locations section:
- There are no listed entries pointing to the
C:\Users\VVKozlov\AppData\Roaming\path - This specific user profile directory doesn't show up in the Trust Center or any other visible Word settings panels
- The
Normal.dotxtemplate is stored in the hidden system directory:C:\Users\VVKozlov\AppData\Roaming\Microsoft\Templates\— this is Word's default, hard-coded location for these templates, and it can't be modified through standard Trust Center configurations
内容的提问来源于stack exchange,提问作者V. V. Kozlov
相关产品推荐
相关产品推荐

