Insights › Essential Eight

Office Macros: Why They’re Blocked and Stay Blocked

Conceptual illustration of a document with hidden code being blocked by a glowing barrier on a navy background.

Macros have quietly powered spreadsheets and reports in Australian offices for decades. They also happen to be one of the most reliable ways attackers get malicious code onto a business computer. That is why, if you have opened a downloaded Word or Excel file lately and seen a red banner telling you macros have been blocked, it was not a glitch. It was a deliberate security control, and in most cases it is doing exactly what it should.

Configuring Microsoft Office macro settings is one of the eight controls in the Australian Signals Directorate’s ACSC Essential Eight, the government’s baseline for stopping common cyber attacks. This article explains what a macro is, why macros became such a popular attack tool, what Microsoft changed to blunt the threat, and how your business can keep the useful macros running while shutting the dangerous ones out.

What is a macro, exactly?

A macro is a small program stored inside an Office file. It is written in a language called Visual Basic for Applications, or VBA, and it lets a document do things automatically that a person would otherwise do by hand. A well built macro can pull figures from several sheets into one summary, format a monthly report the same way every time, or fill in a template at the click of a button. For finance teams and admin staff, a good macro can save real hours.

The catch is that a macro is code, and code can be told to do almost anything the person opening the file could do. It can reach out to the internet, download another program, change files, or launch commands on the computer. Office cannot easily tell the difference between a macro that tidies your invoices and a macro that quietly installs malware. To the software, both are just instructions in a document.

Why macros became an attacker’s favourite tool

For years, malicious macros were one of the most common ways criminals broke into businesses. The reason is simple: a document feels safe. Staff open spreadsheets and Word files hundreds of times a week without a second thought, so a booby-trapped invoice or resume does not trigger the same caution that an unfamiliar program would.

The attack usually followed the same pattern. A convincing email arrived with an attachment, often dressed up as an invoice, a delivery notice, or a job application. The document itself looked blank or blurry, with a message urging the reader to “enable content” or “enable editing” to see it properly. That single click ran the hidden macro, which then downloaded the real payload: banking trojans, credential stealers, or the first stage of a ransomware attack. Many of the most damaging malware families of the last decade spread this way.

Because the malicious code often lives inside the document rather than as a separate file, traditional antivirus sometimes missed it. And because the whole thing depended on tricking a person into one click, it sidestepped a lot of technical defences. That combination of low cost and high success rate is exactly why macros stayed on the attackers’ menu for so long, and why phishing emails so often carried a macro-enabled attachment.

How a malicious macro reaches your team

Malicious macros almost always arrive from outside the business. The common delivery routes are worth knowing, because they show why blocking macros from untrusted sources matters so much:

The thread running through all of these is that the file did not originate inside your trusted systems. A macro written by your own accountant and stored on your company drive is a very different thing from a macro inside a spreadsheet a stranger emailed you this morning. The whole point of good macro settings is to let the first one run and stop the second one cold.

What Microsoft changed, and why the banner appears

In 2022, Microsoft made a significant change to how Office handles macros. From that point, VBA macros in files that came from the internet are blocked by default. When someone opens such a file, they no longer see a friendly “enable content” button. Instead they see a red Security Risk banner explaining that macros have been blocked because the source of the file is untrusted. There is a “Learn More” link, but no one-click way to simply run the code.

This works through a Windows feature called Mark of the Web. When a file is downloaded from the internet, saved from an email attachment, or otherwise arrives from an untrusted zone, Windows quietly tags it with a hidden marker recording where it came from. Office reads that marker. If the file is tagged as coming from the internet, its macros are blocked. The change applies to Word, Excel, PowerPoint, Access, Visio, Publisher, and Project on Windows. It does not apply to Office on Mac, on mobile, or in the browser.

This one change closed a door that attackers had leaned on for years. It is not a complete fix, because criminals adapted by moving to other file types and container formats that do not always carry the Mark of the Web. But it removed the easy path, and it is a big reason macro-based attacks are less dominant than they once were. The banner you see is that protection working.

What the Essential Eight asks businesses to do

Microsoft’s default block is a strong start, but the Essential Eight goes further because it does not want to rely on default settings that a user might be able to change. The ACSC guidance on restricting Office macros sets out a clear approach that any business can adopt:

The principle behind all of this is least privilege: give each person only the capability they actually need. Most staff never write or rely on a macro, so for them the safest and simplest setting is off. The smaller group who do depend on macros get a controlled path that keeps the useful ones working without opening the door to everything else. This is the same thinking behind application control, another of the Essential Eight, which only lets approved software run.

Managing macros without breaking the business

The fear that stops many owners acting is that turning macros off will break a spreadsheet the finance team cannot live without. That is a fair concern, and it is why the right move is not a blunt switch but a short, deliberate process.

Start by finding out who actually uses macros. In many small businesses the honest answer is almost nobody, or one or two people running a single tool. Ask around, and check whether the files people rely on genuinely contain macros or just look complicated. Once you know where the real need sits, you can turn macros off for everyone else with confidence, which is the change that removes most of the risk for the least disruption.

For the people who do need macros, set up a trusted location: a specific folder that normal users cannot save into, where your approved macro-enabled files live. Anything run from there is allowed; anything opened from an email or download is not. If your business has the capability, having a trusted publisher digitally sign your in-house macros is even stronger, because the signature proves the file is yours and has not been tampered with. Your IT provider can usually configure both of these through group policy in an afternoon.

Finally, back the technical settings with a simple rule for staff: if a document you were not expecting asks you to enable content or enable macros, do not do it. Treat that prompt as a warning sign and check with the sender or your IT support first. Combined with the settings above, that habit closes off one of the oldest and most damaging tricks in the book. Blocking macros properly also removes a common first step in ransomware attacks, which makes it well worth the small effort.

Find out where you stand

Macro settings are just one of the controls that decide how exposed your business is. If you are not sure whether yours are configured safely, or how the rest of your defences measure up, our free self-assessment is a good place to start. You answer 27 plain-English questions about how your business works, and you get a personalised PDF report mapped to the ACSC Essential Eight, ISO 27001, and SOC 2. It takes about 5 to 10 minutes, there is nothing to install, and the report is yours instantly.

Take the free SecurityScore assessment and see exactly where your business stands today.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading