How to Force Documents to Open in Protected View on Domain-Joined Computers
Question details
The user needs to configure domain-joined computers so that documents opened from a network file server trigger Protected View without restricting the ability to save.
- Product
- Microsoft Office
- Device & OS
- not provided
- Scenario
- Accessing documents from a network file server after moving workstations to a new domain environment.
- Observed behavior
- Documents from the file server open as trusted files, bypassing Protected View. Enabling File Block Settings forces Protected View but actively prevents users from saving the documents.
Ensure you have administrative privileges to configure Group Policy Objects (GPO) on your domain controller and have the latest Microsoft Office Administrative Templates (ADMX/ADML) installed.
Configure Group Policy for Office Trust Center
Use Group Policy settings to explicitly disable trusted network locations, ensuring documents from file servers trigger Protected View automatically.
By default, domain-joined computers may place network file servers into the Local Intranet zone, automatically trusting the files. Deploying a specific Group Policy overrides this behavior.
Download and install the Microsoft Office administrative templates tailored to your specific version of Office.
Launch the Group Policy Management Console (GPMC) or the Local Group Policy Editor on the domain controller.
Navigate the folder tree to User Configuration > Administrative Templates > Microsoft Office > Security Settings (or Trust Center).
Locate the policy regulating Trusted Locations. Configure the settings to disable trusted locations and explicitly prevent network locations from being trusted.
Review Domain Policies with the Microsoft 365 Administrator
If local or domain-level Group Policy adjustments do not resolve the issue, consult your Microsoft 365 administrator to identify conflicting tenant-level security configurations.
Try WPS Office for Simplified Document Security
Configuring complex Group Policy settings for Microsoft Office Protected View can be tedious and prone to domain conflicts. WPS Office provides a free, lightweight, and highly compatible alternative, offering straightforward local security configurations without heavy administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the clear on-screen instructions to deploy the lightweight suite.
- 3. Open Network Files Securely: Access your file server documents directly through WPS Office with high compatibility and built-in security features.

Frequently Asked Questions
Why do domain-joined computers bypass Protected View for network files?
When a computer joins a domain, Windows often automatically categorizes network file servers into the Local Intranet zone, which is trusted by default. This automatic trust overrides the standard Protected View triggers that normally apply to downloaded or external files.
Can I use File Block Settings to achieve the same result?
While File Block Settings can successfully force documents into Protected View, this method also restricts users from saving or editing the files, which typically disrupts normal business workflows. Using Group Policy to manage Trusted Locations is the recommended approach.
Where are the Trust Center settings located in the Group Policy Editor?
After importing the correct Microsoft Office Administrative Templates, you can find the relevant configurations under User Configuration > Administrative Templates > Microsoft Office > Security Settings (or Trust Center).




