Skip to main content

Macro Security for Microsoft Office

Why macros are a threat, and the approaches you can take to protect your systems.

Office Macro
Microsoft Word showing a macro security warning. The document in the background is trying to persuade the user to enable macros by claiming that they have forgotten to pay an invoice

This guidance describes how administrators can help protect their systems from malicious Microsoft Office macros. It outlines why macros are a threat, and the approaches you can take to protect your devices.



1. Disable macros where they're not used

If your organisation does not use macros, they should be turned off entirely.

If you cannot yet turn macros off, you should work on replacing the macros that your business relies on, so that you can turn them off entirely in the future.

Larger organisations should consider only enabling macros for the specific groups or teams that need them. This allows training to be better-focused and appropriately targeted for these smaller sets of users, to help them understand social engineering techniques and agree sensible protective measures.

You should note that:

  • currently supported versions of Microsoft Office on macOS and Windows have the macro engine enabled by default; though some newer versions of the product attempt to block macros that have come from the Internet as described below. You should not rely on prompts that offer the user to click a button before any macros can run - it is relatively simple to trick the user into clicking this button, so you cannot rely on it as a mitigation.
  • Macros on Windows are configured per-application. If you use macros in some Office applications and not others, you should disable them in the applications where they are not used. For example, if your organisation only uses macros in Excel, you can disable them in Word, PowerPoint, Visio, Access and Publisher. Note that OneNote does not support macros.
  • Macros on macOS are configured for the entire Office suite so you should aim to entirely disable them.

Excel also has an older macro engine on Windows that has been retained for backwards compatibility. Almost all organisations should be able to safely turn it off. We recommend using the "Prevent Excel from running XLM macros" setting in group policy so that users cannot be socially engineered into turning it back on.

2. Reduce your dependency on macros

If you currently use macros, start replacing them with the modern safe alternatives so that you can disable macros completely in the longer term.

Prioritise replacing macros that are incompatible with the attack surface reduction (ASR) rules listed below. Modern approaches to office automation that can replace macros include:

  • automating data flows using modern no-code alternatives such as Power Automate and Office Scripts
  • using the more powerful native functions added to recent versions of Excel such as XLOOKUP and LAMBDA to manipulate data
  • connecting to data sources using the native Power Query engine in Excel
  • building custom web apps that support your business processes, connecting to data in Office 365 using Microsoft Graph

3. Disable high-risk macro capabilities

Windows

Windows Defender attack surface reduction (ASR) rules on Windows can be configured to disable some of the abilities of malicious macros.

You do not need to set these if you have disabled all use of macros in your organisation. If you do allow some macros to run, you should aim to enable all of the suggested mitigations.

They be initially run in audit mode to allow you to confirm that the macros that your organisation uses will continue to work properly. ASR rules also affect the behaviour of other Office features (such as Add-ins), so will require testing prior to broad deployment in organisations that rely on third party Office plugins.

We recommend enabling a range of ASR rules in our Windows guidance. The ones that best target the threat from malicious macros are:

macOS

Office on macOS uses the platform’s sandbox to limit the damage caused by a malicious document. We recommend deploying preferences to strengthen the default configuration of the Office sandbox to further reduce the impact of running malicious macros.

The macro security preferences that best target the threat from malicious macros on macOS are:

4. Use an anti-malware product to detect malicious behaviour in macros

You can reduce the chance of a malicious macro reaching a user if you use an anti-malware product that includes behavioural analysis for macro-enabled Office documents. It could be a part of your email service, or a feature of the anti-malware software on the user’s device.

Organisations using an antivirus that uses Microsoft’s AMSI interface (as recommended in the NCSC's device security guidance for Windows) will have the ability to detect malicious macros even if the malicious intent is cleverly disguised. You should configure the feature to scan all documents, as the default is to only scan those that Office has identified as having come from the Internet.

A dialog box alerting the user that a malicious macro has been detected by your virus scanner

We recommend that devices connected to the Internet are configured in line with the NCSC’s device security guidance. These configurations include a range of mitigations that help protect against malware. While an application allow list is unlikely to prevent malicious macros themselves from running, a configuration such as the one suggested in the guidance for Windows and macOS is a particularly effective way of blocking malware and ransomware that is downloaded by (or extracted from) an Office macro.

5. Disable macros unless they are in trusted files

Office on Windows can also be configured to only allow macros if the file is loaded from a trusted location, such as a specific folder, file share or website. Your organisation will need to define that list of trusted locations. We recommend that macros are only permitted to run from a trusted location, such as a network share that only trusted administrators have written access to.

The antivirus integration described above does not apply to macros in trusted files by default, as many organisations rely on macros that exhibit similar behaviours to malware. We recommend that you override this default as described above so that all trusted files are scanned for malicious behaviour.

Organisations that have a code signing service can choose to configure Office on Windows to only allow digitally signed macros to run. However, the setting allows users to choose to run any macro that has a valid signature - there is no option to only allow macros that have been signed by a specific list of trusted publishers.

6. Block macros from the internet

Office 2016 on Windows introduced the ability for an organisation to block macros in files received from the internet except those that have a digital signature from a publisher that the organisation has chosen to trust. This makes it more difficult to socially engineer users into bypassing the warning.

Since January 2023, this setting has been enabled by default in the Microsoft 365 versions of Office Apps. You should confirm whether you have deployed version 2206 or newer. Note that the perpetual versions of Office such as Office LTSC 2021 or Office 2019 do not have the setting enabled by default.

Macros are blocked from the Internet by default on Windows in S mode.

Image shows macros are blocked from the Internet by default on Windows in S mode.

Note that it is usually not practical to block the file types that can contain macros at your email or internet gateway as they can be found in commonly used legacy formats (such as .RTF .DOC and .DOT), as well as the newer formats that explicitly mark themselves as containing a macro (such as .DOCM and .DOTM).



Published

Reviewed

Version

3.0