Skip to content
arrow_back
search
E8-RM-ML3.3 bolt ASD Essential Eight

Only privileged users can modify content in Trusted Locations

Ensure that only specific users can edit trusted macro locations to prevent malicious code.

record_voice_over

Plain language

This control ensures that only certain trusted people can change sensitive macro settings in Microsoft Office. These settings are special locations where Office macros can run. If unqualified people change these settings, it could allow harmful code to be run unknowingly, which could compromise your entire system.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

RM

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.
bolt ASD Essential Eight E8-RM-ML3.3
priority_high

Why it matters

If unauthorised users can modify Trusted Locations, malicious macros may execute without warning, compromising systems and data integrity.

settings

Operational notes

Restrict Trusted Locations to privileged macro reviewers only; audit NTFS/share ACLs and monitor changes so non-privileged users cannot write content there.

Mapping detail

Mapping

Direction

Controls