Skip to content
arrow_back
search
E8-RM-ML1.1 bolt ASD Essential Eight

Disable Microsoft Office macros for users without a business need

Ensure only users with a specific business need can run Microsoft Office macros.

record_voice_over

Plain language

This control is about stopping unauthorised users from using Microsoft Office macros unless they have a clear business reason to do so. Macros can run harmful code if used by the wrong people, potentially leading to data theft or damage. By limiting who can use them, you're reducing the risk of a cyber attack on your organisation.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

RM

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
bolt ASD Essential Eight E8-RM-ML1.1
priority_high

Why it matters

If users without a business need can run Office macros, malicious code may execute, leading to data compromise and operational disruption.

settings

Operational notes

Maintain an approved list of users who need Office macros, review it regularly, and disable macros by default for all others.

Mapping detail

Mapping

Direction

Controls