Restrict Microsoft Office macros
Restrict Microsoft Office macros is the Essential Eight mitigation strategy governing embedded Visual Basic for Applications code in Office files. It requires macros to be disabled for users without a demonstrated business requirement, blocked in files originating from the internet, scanned by antivirus, and locked against user modification of the settings.
Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).
On this page 5 sections
Restrict Microsoft Office macros at a glance
What each maturity level requires
Requirements are cumulative: Level Three means everything in Levels One and Two as well. Each level links to that requirement on the matrix.
-
ML1 Maturity Level One
Restrict Microsoft Office macros, Maturity Level One: Macros disabled for users without a demonstrated business requirement (ISM-1671) -
ML2 Maturity Level Two
Restrict Microsoft Office macros, Maturity Level Two: Macros blocked from making Win32 API calls -
ML3 Maturity Level Three
Restrict Microsoft Office macros, Maturity Level Three: Only macros from a sandboxed environment, a Trusted Location, or signed by a trusted publisher may execute
This strategy restricts who can run Microsoft Office macros and which macros may execute. In November 2023, ASD removed macro execution-event logging and added stronger signing requirements at Level Three.
What is required, and where
Maturity Level One requires:
- macros disabled for users without a demonstrated business requirement
- macros in files originating from the internet blocked
- macro antivirus scanning enabled
- macro security settings unable to be changed by users
Maturity Level Two adds a requirement to block macros from making Win32 application programming interface (API) calls.
Maturity Level Three adds these controls:
- only macros from a sandboxed environment, a Trusted Location, or digitally signed by a trusted publisher may execute
- macros are checked for malicious code before being signed or placed in a Trusted Location
- only privileged users responsible for that checking may write to Trusted Locations
- macros signed by an untrusted publisher cannot be enabled through the Message Bar or Backstage View
- V3 signatures are enforced
- the trusted publishers list is validated at least annually
See the requirements matrix for every control at each maturity level.
The requirement that was removed
This is the update's only explicit removal of an Essential Eight requirement. From the Essential Eight maturity model changes:
Due to a lack of native support for macro execution event logging in Microsoft Windows… and advice from incident responders and threat hunters that such events provide limited benefit, the requirement to collect and analyse these events for signs of compromise has been removed.
If a checklist lists macro execution-event logging as an Essential Eight requirement, it is using a pre-November 2023 version of the model.
Note this removal is specific to macro execution events. The broader centralised logging requirement introduced at Maturity Level Two across the framework still applies.
ASD's ranking of macro approaches
ASD's Restricting Microsoft Office macros publication ranks six approaches by security benefit:
| Approach | Security benefit |
|---|---|
| All macros disabled | Very High |
| Only macros digitally signed by trusted publishers | High |
| Only macros from trusted locations | High |
| Users decide, with additional security measures | Medium |
| Users decide, no additional measures | Low |
| All macros enabled | None |
The framework's Level One requirement (disabled for anyone without a demonstrated business need) is effectively "all macros disabled, with exceptions you have to justify".
Commonwealth implementation
Restrict Microsoft Office macros is the best-performing of the eight across Commonwealth entities. ASD's Commonwealth Cyber Security Posture in 2025 has it reaching 81% at Maturity Level Two or above in 2024–25, up from 68%.
Microsoft now blocks macros from the internet by default in supported Office versions. That default helps with one Level One control, but it does not satisfy the strategy by itself. Organisations must still disable macros for users without a demonstrated business requirement, enable antivirus scanning and prevent users from changing the security settings.
The result cannot establish an organisation's overall maturity on its own. Under the weakest-link rule, the lowest of the eight strategy levels determines the overall level.
Macros are still a delivery mechanism
Office files can carry embedded Visual Basic for Applications code, which attackers use to deliver malware. ASD split macro controls out of user application hardening as a separate strategy in the 2017 Strategies to Mitigate Cyber Security Incidents, "to reflect the prevalence of malicious Microsoft Office macros".
Default blocking does not remove the need for Level Three controls. Those requirements address macros placed in locations or signed by publishers the environment trusts: the macro is checked before signing, write access to Trusted Locations is restricted, and signatures are validated.
Sources
- ASD — Restricting Microsoft Office macros — Last updated 27 November 2023
- ASD — Essential Eight maturity model — Last updated 27 November 2023
- ASD — Essential Eight maturity model changes — 27 November 2023
- ASD — The Commonwealth Cyber Security Posture in 2025
Common questions
Do we still have to log macro execution events?
No. ASD removed the requirement in November 2023 because Microsoft Windows lacks native support for macro execution-event logging. Incident responders and threat hunters also advised that the events provide limited benefit. Guidance that still requires this logging uses a pre-November 2023 model.
Is this strategy called "configure Microsoft Office macro settings"?
Both names are current ASD wording. The maturity model uses "restrict Microsoft Office macros". The separate 2017 Strategies to Mitigate Cyber Security Incidents publication uses "configure Microsoft Office macro settings". ASD created it as a separate strategy "to reflect the prevalence of malicious Microsoft Office macros".
What is a V3 signature and why does it matter?
V3 is a newer digital signature format for macros, required at Maturity Level Three. ASD introduced it after identifying a vulnerability that allowed macro code to be altered without invalidating an older digital signature.
Are trusted locations acceptable?
Yes, with care. ASD discourages trusted documents but says trusted locations, "when implemented in a secure manner, can allow organisations to balance both their business and security requirements". At Maturity Level Three only privileged users responsible for checking macros may write to trusted locations, and macros must be verified free of malicious code before being placed there.
Read next
-
Essential Eight requirements matrix
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
-
Application control
Application control restricts execution to an organisation-approved set. ASD treats it as one of the most effective controls for preventing malicious code from running.
-
User application hardening
ASD's user application hardening covers browsers, Office, PDF readers and PowerShell. It does not describe how to harden software an organisation develops.
Essential Eight
Need this assessed rather than explained?
We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.