Skip to content
arrow_back
E8-AH-ML2.5boltASD Essential Eight

Configure Microsoft Office to prevent activation of OLE packages

Ensure Microsoft Office is set up to stop risky linking and embedding features.

record_voice_over

Plain language

This control is about setting up Microsoft Office so it doesn't automatically activate certain objects and packages that could be harmful. Imagine opening a Word document, and it triggers something bad on your computer without you knowing. This control helps prevent that sneaky behaviour.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML2

Official control statement

Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.
boltASD Essential EightE8-AH-ML2.5
priority_high

Why it matters

Without this control, malicious OLE packages in Office documents may activate and run code, causing data theft or system compromise.

settings

Operational notes

Enforce GPO/Intune settings that block OLE package activation in Office, and validate via test docs after Office updates or policy changes.

build

Implementation tips

  • The IT team should configure Microsoft Office settings to block Object Linking and Embedding (OLE) packages. This can be done through group policy settings to ensure the feature is disabled for all users.
  • System administrators should regularly update Office applications to the latest versions. Updates often include security improvements that reinforce these settings.
  • Security officers should develop and distribute guidelines explaining why OLE packages are disabled to help users understand the importance of this measure.
  • Network administrators should monitor network traffic for any unauthorised attempts to activate OLE packages, using security tools to alert them of such activities.
fact_check

Audit / evidence tips

  • AskHave the Microsoft Office security settings been configured to block OLE package activation?
  • GoodThe group policy settings show OLE activation is blocked for all users, and the settings cannot be changed by end users
link

Cross-framework mappings

How E8-AH-ML2.5 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(2)expand_less
Annex A 8.1E8-AH-ML2.5 requires a Microsoft Office endpoint configuration to prevent activation of OLE packages
Annex A 8.8E8-AH-ML2.5 requires Microsoft Office to prevent activation of OLE packages as a measure to reduce exposure to a known attack technique u...
extensionDepends on(1)expand_less
Annex A 8.9E8-AH-ML2.5 requires Microsoft Office to be configured to prevent activation of OLE packages

ASD ISM

ControlNotesDetails
sync_altPartially overlaps(5)expand_less
ISM-0289ISM-0289 requires evaluated products to be configured, administered and operated in an evaluated configuration and in accordance with ven...
ISM-1667E8-AH-ML2.5 requires Microsoft Office to be configured to prevent activation of OLE packages to reduce embedded-object execution risk
ISM-1668E8-AH-ML2.5 requires Microsoft Office to prevent activation of OLE packages to limit execution of embedded content
ISM-1669E8-AH-ML2.5 requires disabling OLE package activation in Microsoft Office to reduce embedded object execution and related exploitation
ISM-1673ISM-1673 requires blocking Win32 API calls by Office macros to constrain macro capability
handshakeSupports(1)expand_less
ISM-1601E8-AH-ML2.5 requires Microsoft Office to be configured to prevent activation of OLE packages
extensionDepends on(2)expand_less
ISM-1913E8-AH-ML2.5 requires implementing a defined Microsoft Office configuration that prevents OLE package activation
ISM-1915E8-AH-ML2.5 requires a specific approved configuration in Microsoft Office to prevent activation of OLE packages
linkRelated(5)expand_less
ISM-1536ISM-1536 requires Microsoft Office to be configured to block activation of OLE packages to reduce exploitation of embedded objects
ISM-1542E8-AH-ML2.5 requires Microsoft Office to be configured to prevent activation of Object Linking and Embedding (OLE) packages
ISM-1798ISM-1798 requires that secure configuration guidance is produced and made available to consumers for software
ISM-1858ISM-1858 requires organisations to harden IT equipment using ASD and vendor guidance, choosing the most restrictive configuration where g...
ISM-2110ISM-2110 requires user applications to be hardened in accordance with ASD and vendor hardening guidance, applying the most restrictive gu...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all User application hardening controls, or browse the full Essential Eight mitigation strategies library.

Mapping detail

Mapping

Direction

Controls