logo

Disable Office application macros and block macro-enabled Office files to prevent cyberattacks

ID: 79cf4c0f-3359-5c78-ba3e-024bcbee0391

STIX ID: report--79cf4c0f-3359-5c78-ba3e-024bcbee0391

Feed Name: ThreatLocker Blog

Date Published: 2025-06-26

Date Updated: 2026-05-01

...
...

This document provides step-by-step guidance to reduce risk from macro-enabled Office files by configuring policies in Microsoft 365 (config.office.com), Windows Group Policy, and ThreatLocker. It recommends enabling “Block macros from running in Office files from the internet” and setting VBA Macro Notification policies per Office app, while clarifying policy precedence (cloud/Group Policy over Trust Center) to ensure consistent enforcement across the organization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.