Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy

Key Takeaways

  • This policy setting allows you to block macros from running in Office files that come from the Internet.
  • The Block Internet Macros for Office Applications policy helps prevent macros from running in Office files downloaded from the internet.
  • The policy can help reduce security risks caused by malicious macros in untrusted Office documents.
  • The setting can be configured for supported Microsoft Office applications, including Word, Excel, PowerPoint, Access, and Visio.

Let’s learn how to Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy. Microsoft made changes in the default behavior of Internet Macros for Office Applications. Microsoft Office macros are useful for automating repetitive tasks and performing actions within applications such as Microsoft Word, Excel, PowerPoint, Access, and Visio. However, macros can also create a security risk when they are included in files downloaded from the internet.

Table of Contents

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy

You can use Intune Settings Catalog or Group Policy to block the internet macro download for Microsoft office applications on Windows 11 devices. This will block macros from running in Office files from the Internet. The Block Internet Macros for Office Applications policy helps organizations protect users from this type of security risk. When configured, the policy prevents macros from running in supported Microsoft Office files that originate from the internet.

Block Internet Macros for Office Applications

Let’s check end-user experience and workflow when Block Internet Macros for Office Applications policy is implemented. The Office app Trust bar shows the following error when blocking internet macros via Cloud policy or via default settings implemented for all the users.

SECURITY RISK Microsoft has blocked macros from running because the source of this file is untrusted.

Patch My PC

Confirm the Macro Policy is Set or not

You can use the following method to confirm whether the Office 365 macro policies set on Windows devices or not. The policy was set to Disabled or Not Configured, then the app would check the settings under:

  • File > Options
  • Trust Center > Trust Center Setting.
  • Macro Settings.
  • The default is set to “Disable all macros with notification,” which allows users to enable content in the Trust Bar.

Create Intune Cloud Policy to Block Macros from Internet

To begin, sign in to the Microsoft Intune admin center and navigate to Devices > Windows > Configuration profiles. Select Create > New policy to start creating a new configuration profile for Windows devices. Choose Windows 10 and later as the platform and select Settings catalog as the profile type.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.1
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.1

Choose Windows 10 and later as the platform and select Settings catalog as the profile type. The Settings Catalog allows administrators to search for and configure individual policy settings, including the settings required for the Block Internet Macros for Office Applications policy. Click on Create button.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.2
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.2

Basic Tab

In the Basics section, enter a meaningful name for the policy. For example, you can use Block Internet Macros for Office Applications so that administrators can easily identify the purpose of the profile later. You can also add a description such as Block macros from running in Office files from the Internet. A clear description helps other administrators understand why the policy was created and what security setting it manages before opening the profile configuration.

  • Optionally, enter a Description for the policy – Block macros from running in Office files from the Internet.
  • Select Next to continue.
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.3
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.3

Configuration Settings

In Configuration settings, click Add settings to browse or search the catalog for the settings you want to configure. In this case, to block internet macros from running on office apps.On the Settings Picker windows, use the search box and type macros from running in Office files from the Internet, and click Search.

  • Block macros from running in Office files from the Internet (User)
  • Use commas “,” among search terms to lookup settings by their keywords “macros from running in Office files from the Internet.”.
  • The Browse by category – 1 results in the “Trust Center” subcategory – Setting name.
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.4
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.4

Block Internet Macros for Office Applications Policy is Disabled by Default

The Block macros from running in Office files from the Internet setting is not enabled by default through the Intune policy. This means administrators must explicitly configure and enable the setting if they want Intune to enforce macro blocking for the selected Office applications.

When the setting remains unconfigured or disabled, the policy does not actively enforce this specific macro-blocking behavior through Intune. Therefore, organizations that want centralized protection should enable the appropriate setting for the required Office applications.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.5
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.5

Enable the Block Internet Macros for Office Applications Policy

This policy setting allows you to block macros from running in Office files from the Internet. If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center.

The disabled macro policy is available for 5 office applications such as Access, Excel, PowerPoint, Visio, and Word. You can use the settings called “Block macros from running in Office files from the Internet (User)” to change the default behavior of the Office application towards enabling the Macros received from the internet.

  • Microsoft Access 2016 – Application Settings > Security > Trust Center – 11 of 12 settings in this subcategory are not configured.
  • Microsoft Excel 2016 – Excel Options > Security > Trust Center – 15 of 16 settings in this subcategory are not configured.
  • Microsoft PowerPoint 2016 – PowerPoint Options > Security > Trust Center – 13 of 14 settings in this subcategory are not configured.
  • Microsoft Visio 2016 – Visio Options > Security > Trust Center – 114 of 115 settings in this subcategory are not configured.
  • Microsoft Word 2016 – Word Options > Security > Trust Center – 18 of 19 settings in this subcategory are not configured.

Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. Macros will be allowed to run if the Office file is saved to a trusted location or was previously trusted by the user. If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.

  • Use the slider (move to the right) to enable the block policy for running the macros from office files, as shown in the below screenshot.
  • Follow the same steps for all 5 applications.
  • Click on Next.
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.6
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.6

Configure Scope Tags

The Scope tags section allows administrators to apply role-based access controls to the policy. In Scope tags you can assign a tag to filter the profile to specific IT groups. Add scope tags (if required) and click Next.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.7
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.7

Assign the Block Internet Macros for Office Applications Policy

In the Assignments section, select the Microsoft Entra ID groups that should receive the Block Internet Macros for Office Applications policy. You can assign the policy to the appropriate user or device groups based on your organization’s deployment requirements. Here, I selected the HTMD-Test Policy group and HTMD CPC Test group.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.8
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.8

Review and Create the Block Internet Macros

The Review + create page displays a summary of the policy configuration. Review the policy name, selected Office application settings, scope tags, and group assignments to ensure that everything is configured correctly. Once you confirm the configuration, select Create to save and deploy the Block Internet Macros for Office Applications policy. Intune will then begin processing the policy and delivering it to the targeted users or devices.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.9
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.9

Monitor the Block Internet Macros for Office Applications

After deployment, you can monitor the Block Internet Macros for Office Applications policy from the Intune admin center. Open the configuration profile and check the device and user status to see whether the policy was successfully applied.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.10
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.10

Intune Policy Deployment

You can check Intune settings catalog profile report from Intune Portal, which provides an overall view of device configuration policies and deployment status. The next step is to look into the event logs and confirm whether the policy is applied or not. Event Log path for Intune logs – > Applications and Services -> Microsoft->Windows->DeviceManagement-Enterprise-Diagnostics-Provider->Admin

Policy Information
MDM PolicyManager: Set policy string, Policy: (L_BlockMacroExecutionFromInternet), Area:
(access16~Policy~L_MicrosoftOfficeaccess~L_ApplicationSettings~L_Security~L_TrustCenter),
EnrollmentID requesting merge: (EB427D85-802F-46D9-A3E2-D5B414587F63), Current User:
(S-1-12-1-3449773194-1083384580-749570698-1797466236), String: (<enabled/>), Enrollment Type:
(0x6), Scope: (0x1).
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.11
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.11

Remove Assigned Groups from the Block Internet Macros for Policy

If you no longer want a particular group to receive the policy, open the Block Internet Macros for Office Applications configuration profile and edit its assignments. Remove the group that should no longer be included in the deployment. After saving the changes, Intune updates the policy assignment for the affected group. This allows administrators to stop deploying the policy to selected users or devices without deleting the entire configuration profile.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.12
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.12

Delete the Block Internet Macros

If the policy is no longer required, you can permanently remove it from Intune. First, locate the Block Internet Macros for Office Applications policy under Devices > Windows > Configuration profiles. Select the policy and choose Delete, then confirm the deletion when prompted. Once permanently deleted, the configuration profile is removed from Intune and will no longer be available for management.

Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy - Fig.13
Block Internet Macros for Office Applications to Prevent Security Threats using Intune Policy – Fig.13

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair  is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. He is Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11 years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His focus is on Device Management technologies such as Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Leave a Comment