Skip to content
arrow_back
search
E8-RM-ML3.1 bolt ASD Essential Eight

Restrict Microsoft Office macros to only trusted or sandboxed environments

Allow only macros from trusted locations, sandboxes, or signed by trusted publishers.

record_voice_over

Plain language

This control is about making sure that macros in Microsoft Office documents, like Word or Excel, only run if we know they're safe. Macros can automatically execute tasks and, if not controlled, they can be used by hackers to run harmful code on your computer, leading to data breaches or loss.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

RM

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.
bolt ASD Essential Eight E8-RM-ML3.1
priority_high

Why it matters

Unchecked Office macros can deliver malware, enabling data theft and account compromise, disrupting business operations and causing financial loss.

settings

Operational notes

Review and minimise Trusted Locations, validate trusted publishers’ certificates, and ensure macros run only in approved sandboxes; remove stale exceptions.

Mapping detail

Mapping

Direction

Controls