Microsoft is blocking these macros in Office to boost your PC security

The Microsoft Office logo on a laptop open on a table
(Image credit: Shutterstock)

Microsoft is making a small change in the way that Office files downloaded from the internet are handled on PCs — but the change should lead to a huge improvement in computer security.

Specifically, Microsoft said in a blog post last week, it is making it harder to run macros, tiny but powerful scripts — really mini-programs — that can be embedded into Word documents, Excel spreadsheets, and PowerPoint, Access and Visio files. 

"We will continue to adjust our user experience for macros, as we've done here, to make it more difficult to trick users into running malicious code via social engineering while maintaining a path for legitimate macros to be enabled where appropriate via Trusted Publishers and/or Trusted Locations," said Microsoft manager Tristan Davis in the blog post.

The change will begin rolling out in April for users on the Office Preview version 2203. It will then spread to regular consumer and business users and older versions of Office, all the way back to Office 2013, over the next couple of years. Microsoft Office on Macs, Android or iOS devices or the web-based Office won't be affected. 

"This is potentially a game changer for the cybersecurity industry and, more importantly, customers," tweeted Windows security expert Kevin Beaumont. 

Let's say your company has a new name, and so you write a small script that at the click of a mouse changes all instances of "Acme Enterprises" in a Word doc to "Weyland-Yutani Corporation" — that's a macro.

Convenient, right? That's why Microsoft has let Office users write and use macros since the mid-1990s. But hackers quickly began to use macros to spray malware, steal passwords and create remote backdoors in computer systems. 

Malicious macros inserted into innocent-looking Word and Excel files that can be emailed are downloaded are now responsible for a huge chunk of hacking attacks. Beaumont estimates that 25% of ransomware attacks begin with a macro.

Microsoft belatedly caught on to this abuse, so with Office 2007 it introduced what it called "Protected View" for files downloaded from websites or received as email attachments. 

Among other things, Protected View disables macros until the user ( i.e., you) clicks a button labeled "Enable Content" in a yellow bar that says "Security Warning: Macros have been disabled" stretching across the top of the open document or spreadsheet. You've probably seen it.

(Image credit: Microsoft)

Well, Protected View hasn't been enough. Many people view it as an inconvenience rather than a security feature and just click Enable Content anyway. Or hackers trick you into clicking it by instructing you to do so in order to see some amazing or important content. (Here's an example of malware that uses poisoned Office files to spread.)

So Microsoft is changing the color of that bar across the document from yellow to red, and changing its text to "SECURITY RISK: Microsoft has blocked macros from running because the source of this file is untrusted." 

The red banner that Office users will soon see across the top of Office files downloaded from the internet that contain macros.

(Image credit: Microsoft)

It won't let you enable macros until you click a button labeled "Learn More" — no more Enable Content — and read a Microsoft web page that explains why doing so is a really bad idea. 

If you insist on running the macros, the page shows you how, but it's a pain in the patootie. You have to save the file to disk, browse to it in Windows Explorer, right-click the file to view Properties and check "Unblock" in a security setting. 

That's definitely going to annoy some Office users. Microsoft is hoping most of them won't bother to enable macros from now on. But it's going to be better overall for the safety and security of all Windows users.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
Microsoft Edge open on a laptop with the browser's app listing page open on a smartphone in front of it
Microsoft Edge will soon protect you from these scary scams that even Chrome can't
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
Latest in Office Software
Microsoft Office running on a laptop
Hate subscriptions? Microsoft Office 2024 is out now for a one-time fee
UPDF advertorial screenshots
UPDF exclusive deal means you can edit PDFs for less
Microsoft 365 Personal and Family office suite
All your office apps are in one spot with Microsoft 365 Personal and Family plans
how to write a blog post
How to do a hanging indent in Google Docs
how to edit a PDF on Mac
How to Insert text box in Google Docs
An image of a person using a laptop
How to change margins in Google Docs
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Thursday, March 27 (#655)
The Signal app logo displayed on an iPhone, with a screenshot of the Signal app in use displayed on a monitor in the background.
Signal — everything you need to know about the app at the center of the group chat scandal
Robert Downey Jr. revealed as Doctor Doom for "Avengers: Doomsday"
Marvel reveals 'Avengers: Doomsday' casting — the latest updates and every actor
Wyze Cam v3
Wyze adds AI-powered filter to its security cameras to cut down on notifications that are “no big deal”
Mark Grayson (Steven Yeun) as Invincible in his blue suit during a scene from "Invincible" season 3 on Prime Video.
'Invincible' season 4 release window just announced — here's when it's coming
Microsoft Copilot app running on a phone with Microsoft logo in background
Microsoft 365 Copilot debuts new research tools for work: here's what that means