Skip to content
arrow_back
search
E8-AH-ML2.7 bolt ASD Essential Eight

Office productivity suite settings are immutable by users

Ensure users cannot change security settings in office applications.

record_voice_over

Plain language

This control is about making sure that people in the organisation can't change security settings in software like Microsoft Office. This is important because if security settings are altered, it could make the software more vulnerable to attacks, like viruses or hackers trying to steal information.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Office productivity suite security settings cannot be changed by users.
bolt ASD Essential Eight E8-AH-ML2.7
priority_high

Why it matters

Allowing users to change Office suite settings can disable protections like macro controls, increasing malware infection and data breach risk.

settings

Operational notes

Enforce Office security settings via GPO/Intune and routinely audit policy drift so any user-attempted changes are blocked or reverted.

Mapping detail

Mapping

Direction

Controls