Home › Resources › Essential Eight › Restricting Microsoft Office macros

Restricting Microsoft Office macros

One of the eight mitigation strategies in the Essential Eight, checked against 4 tests at Maturity Level One.

Macros automate tasks inside Office documents, and they are also a well-worn route for delivering malware. This strategy blocks macros from untrusted sources while still permitting the vetted ones a team genuinely depends on.

Why it matters

Organisations trade large volumes of documents with customers, suppliers and partners. A macro-enabled spreadsheet from an unfamiliar sender is a textbook delivery method, and default settings frequently let it run.

Where Intelligence Group fits

  • Block macros in files that arrived from the internet
  • Allow only macros that are digitally signed or stored in trusted locations
  • Identify the handful of business-critical macros and vet them
  • Enable macro antivirus scanning where it is available
  • Log macro execution so you can see what actually runs
Where Intelligence Group fits

Intelligence Group rates this strategy from the evidence your organisation already generates, reports the maturity level it supports, and sets out the next step to lift it.

Official guidance: ASD Essential Eight Maturity Model