• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / System Administration / Protect your organization from ransomware by blocking macros in Office 2016 through Group Policy

Protect your organization from ransomware by blocking macros in Office 2016 through Group Policy

2016-04-11 by Jason

Microsoft has updated the available Office 2016 Administrative Templates for Group Policy configuration. The updated admx files include new settings to block macros from running in Word documents, Excel spreadsheets, or PowerPoint presentations that originated from the Internet. Microsoft has provided this updated mitigation to provide control to a popular vector that malware, in particularly ransomware, is taking advantage. If you do not use macros, you can disable them completely through the ‘VBA Macro Notification Settings’ setting. If you use macros, you can use the new setting to selectively block their execution in documents that were downloaded from file-sharing sites or storage providers as well as emails.

To find the settings, download the latest Administrative Templates for Office 2016 and extract them to your central store. Once copied to your central store, you will find the ‘Block macros from running in Office files from the Internet’ setting in the following paths:

  • User Configuration, Administrative Templates, Microsoft Excel 2016, Excel Options, Security, Trust Center
  • User Configuration, Administrative Templates, Microsoft PowerPoint 2016, PowerPoint Options, Security, Trust Center
  • User Configuration, Administrative Templates, Microsoft Word 2016, Word Options, Security, Trust Center

block_macros_tree

The setting can be enabled or disabled. If a document is opened with a macro that is legitimate and needs to be run, users will need to move it to a trusted location in order to allow the macro.

block_macros

Microsoft’s previous level of protection was the Protected View. It warned the user and required elevation to ‘enable editing’ for the restricted content in external files.

macro_doc

Microsoft has put the power in the hands of the enterprise as it was too easy for an end-user to click ‘enable editing’ and run a suspicious file just to make the notice disappear. The user will now receive an alert saying:

“Blocked Content – Macros in this document have been disabled by your enterprise administrator for security reasons.”

office2016_macro_blocked

With ransomware the latest and most profitable route for malicious actors to take, it is recommended to shut the door to macro-based malware by enabling this setting.

For more information, you can see this article from the Microsoft Malware Protection Center and the TechNet article to ‘Plan security settings for VBA macros in Office 2016‘.

Filed Under: Security and Privacy, Software, System Administration Tagged With: microsoft, Microsoft office

Trending

  • Preventing website hacking as a nature video
    In Media, Security and Privacy
  • CNN Now Offering Live Streaming – Follows HBO Go Model For Current Cable Subscribers
    In Entertainment, Hardware, Gadgets, and Products, Media
  • CES 2011 – Day 1 Wrap-Up
    In Entertainment, Hardware, Gadgets, and Products, News

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • Command line to take ownership and change permissions Command line to take ownership and change permissions
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
  • How Digital Technology Brought the Rise of the CMO   How Digital Technology Brought the Rise of the CMO  
  • How to Purchase Cryptocurrencies? How to Purchase Cryptocurrencies?
  • Top 6 necessary aspects to consider when hiring Angular developers Top 6 necessary aspects to consider when hiring Angular developers
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • The Latest Innovations In Payment Technology
  • How Digital Technology Brought the Rise of the CMO  

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2023 · Magazine Pro Theme on Genesis Framework · WordPress · Log in