Skip to content
arrow_back
search
ISM-1891 policy ASD Information Security Manual (ISM)

Restrict Non-V3 Signed Macros in Microsoft Office

Microsoft Office can't enable macros signed with old methods via common interfaces.

record_voice_over

Plain language

This control means that only the latest and most secure type of digital signatures, known as V3 signatures, can enable macros in Microsoft Office. This is important because older types of signatures can make it easier for harmful software to sneak in and cause problems, like stealing your data or damaging your files.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.
policy ASD Information Security Manual (ISM) ISM-1891
priority_high

Why it matters

If users can enable macros signed with non‑V3 certificates via Message Bar/Backstage, malicious macros may run, causing compromise and data loss.

settings

Operational notes

Configure Office/GPO to prevent enabling non‑V3 signed macros via Message Bar/Backstage; regularly test with sample signed macros and audit policy settings.

Mapping detail

Mapping

Direction

Controls