Excel 4.0 (XLM) macros now restricted by default for customer protection

Published Jan 19 2022 11:38 AM 16.8K Views
Microsoft

In July of 2021, we released a new Excel Trust Center setting option to restrict the usage of Excel 4.0 (XLM) macros. As planned, we have now made this setting the default when opening Excel 4.0 (XLM) macros. This will help our customers protect themselves against related security threats.

 

Customers can manage this setting by following the instructions shared in the original blog: 

Restrict usage of Excel 4.0 (XLM) macros with new macro settings control - Microsoft Tech Community.

 

Availability:

This setting now defaults to Excel 4.0 (XLM) macros being disabled in Excel (Build 16.0.14427.10000)
Per the original blog post, Administrators can also use the existing Microsoft 365 applications policy control to configure this setting. Get the latest Office Administrative Template files.

The Group Policy setting “Macro Notification Settings” for Excel can be found in the following path and registry key:

  • Group Policy Path: User configuration > Administrative templates > Microsoft Excel 2016 > Excel Options > Security > Trust Center.
  • Registry Key Path: Computer\HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Office\16.0\excel\security

In addition, this policy setting can be managed with:

Administrators also have the option to completely block all XLM macro usage (including in new user-created files) by enabling the Group Policy, “Prevent Excel from running XLM macros”, which is configurable via Group Policy Editor or registry key.

 

XLM is disabled by default in the September fork, version 16.0.14527.20000+

  • Current Channel builds 2110 or greater (first released in October)

  • Monthly Enterprise Channel builds 2110 or greater (first released in December)

  • Semi-Annual Enterprise Channel (Preview) builds 2201 or greater (we create this in January 2022, but it first ships in March 2022)

  • Semi-Annual Enterprise Channel builds 2201 or greater (will ship July 2022)

To learn more:

Restrict usage of Excel 4.0 (XLM) macros with new macro settings control - Microsoft Tech Community

Working with Excel 4.0 macros - Excel
Enable or disable macros in Office files - Office Support

 

Subscribe to our Excel Blog and join our Excel Community to stay connected with us and other Excel fans around the world.

 

1 Comment
%3CLINGO-SUB%20id%3D%22lingo-sub-3057905%22%20slang%3D%22en-US%22%3EExcel%204.0%20(XLM)%20macros%20now%20restricted%20by%20default%20for%20customer%20protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3057905%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20July%20of%202021%2C%20we%20released%20a%20new%20Excel%20Trust%20Center%20setting%20option%20to%20restrict%20the%20usage%20of%20Excel%204.0%20(XLM)%20macros.%20As%20planned%2C%20we%20have%20now%20made%20this%20setting%20the%20default%20when%20opening%20Excel%204.0%20(XLM)%20macros.%20This%20will%20help%20our%20customers%20protect%20themselves%20against%20related%20security%20threats.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECustomers%20can%20manage%20this%20setting%20by%20following%20the%20instructions%20shared%20in%20the%20original%20blog%3A%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexcel-blog%2Frestrict-usage-of-excel-4-0-xlm-macros-with-new-macro-settings%2Fba-p%2F2528450%22%20target%3D%22_blank%22%3ERestrict%20usage%20of%20Excel%204.0%20(XLM)%20macros%20with%20new%20macro%20settings%20control%20-%20Microsoft%20Tech%20Community%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAvailability%3A%3C%2FP%3E%0A%3CP%3EThis%20setting%20now%20defaults%20to%20Excel%204.0%20(XLM)%20macros%20being%20disabled%20in%20Excel%20(Build%2016.0.14427.10000)%3CBR%20%2F%3EPer%20the%20original%20blog%20post%2C%20Administrators%20can%20also%20use%20the%20existing%20Microsoft%20365%20applications%20policy%20control%20to%20configure%20this%20setting.%20Get%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fdownload%2Fdetails.aspx%3Fid%3D49030%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Elatest%20Office%20Administrative%20Template%20files.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThe%20Group%20Policy%20setting%20%E2%80%9CMacro%20Notification%20Settings%E2%80%9D%20for%20Excel%20can%20be%20found%20in%20the%20following%20path%20and%20registry%20key%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EGroup%20Policy%20Path%3A%20User%20configuration%20%26gt%3B%20Administrative%20templates%20%26gt%3B%20Microsoft%20Excel%202016%20%26gt%3B%20Excel%20Options%20%26gt%3B%20Security%20%26gt%3B%20Trust%20Center.%3C%2FLI%3E%0A%3CLI%3ERegistry%20Key%20Path%3A%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20Computer%5CHKEY_CURRENT_USER%5CSOFTWARE%5CPolicies%5CMicrosoft%5COffice%5C16.0%5Cexcel%5Csecurity%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EIn%20addition%2C%20this%20policy%20setting%20can%20be%20managed%20with%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3ECloud%20policies%3C%2FSTRONG%3E%20may%20be%20deployed%20with%20the%20%3CA%20href%3D%22https%3A%2F%2Fconfig.office.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EOffice%20cloud%20policy%20service%3C%2FA%3E%20for%20policies%20in%20HKCU.%26nbsp%3B%20Cloud%20policies%20apply%20to%20a%20user%20on%20any%20device%20accessing%20files%20in%20Office%20apps%20with%20their%20AAD%20account.%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fdeployoffice%2Fadmincenter%2Foverview-office-cloud-policy-service%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ELearn%20more%20about%20Office%20cloud%20policy%20service%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EADMX%20policies%3C%2FSTRONG%3E%20may%20be%20deployed%20with%20%3CA%20href%3D%22https%3A%2F%2Fendpoint.microsoft.com%2F%23home%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Endpoint%20Manager%3C%2FA%3E%20(MEM)%20for%20both%20HKCU%20and%20HKLM%20policies.%20These%20settings%20are%20written%20to%20the%20same%20place%20as%20Group%20Policy%2C%20but%20managed%20from%20the%20cloud%20in%20MEM.%20There%20are%20two%20methods%20to%20create%20and%20deploy%20policy%20configurations%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fadministrative-templates-windows%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAdministrative%20templates%3C%2FA%3E%20or%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fsettings-catalog%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Esettings%20catalog%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EAdministrators%20also%20have%20the%20option%20to%20completely%20block%20all%20XLM%20macro%20usage%20(including%20in%20new%20user-created%20files)%20by%20enabling%20the%20Group%20Policy%2C%20%E2%80%9CPrevent%20Excel%20from%20running%20XLM%20macros%E2%80%9D%2C%20which%20is%20configurable%20via%20Group%20Policy%20Editor%20or%20registry%20key.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EXLM%20is%20disabled%20by%20default%20in%20the%20September%20fork%2C%20version%2016.0.14527.20000%2B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CP%3ECurrent%20Channel%20builds%202110%20or%20greater%20(first%20released%20in%20October)%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3E%3CP%3EMonthly%20Enterprise%20Channel%20builds%202110%20or%20greater%20(first%20released%20in%20December)%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3E%3CP%3ESemi-Annual%20Enterprise%20Channel%20(Preview)%20builds%202201%20or%20greater%20(we%20create%20this%20in%20January%202022%2C%20but%20it%20first%20ships%20in%20March%202022)%3C%2FP%3E%0A%3C%2FLI%3E%0A%3CLI%3E%3CP%3ESemi-Annual%20Enterprise%20Channel%20builds%202201%20or%20greater%20(will%20ship%20July%202022)%3C%2FP%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CU%3ETo%20learn%20more%3A%3C%2FU%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexcel-blog%2Frestrict-usage-of-excel-4-0-xlm-macros-with-new-macro-settings%2Fba-p%2F2528450%22%20target%3D%22_blank%22%3ERestrict%20usage%20of%20Excel%204.0%20(XLM)%20macros%20with%20new%20macro%20settings%20control%20-%20Microsoft%20Tech%20Community%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Foffice%2Fworking-with-excel-4-0-macros-ba8924d4-e157-4bb2-8d76-2c07ff02e0b8%23%3A~%3Atext%3DTo%2520change%2520macro%2520settings%2520to%2520allow%2520you%2520to%2Cbox%2520for%2520Open%2520is%2520selected.%2520More%2520items...%2520%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EWorking%20with%20Excel%204.0%20macros%20-%20Excel%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Foffice%2Fenable-or-disable-macros-in-office-files-12b036fd-d140-4e74-b45e-16fed1a7e5c6%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EEnable%20or%20disable%20macros%20in%20Office%20files%20-%20Office%20Support%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESubscribe%20to%20our%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fxlblog%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EExcel%20Blog%3C%2FA%3E%26nbsp%3Band%20join%20our%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FExcelCommunity%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EExcel%20Community%3C%2FA%3E%26nbsp%3Bto%20stay%20connected%20with%20us%20and%20other%20Excel%20fans%20around%20the%20world.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-3057905%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22trustcentermacro.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F340789iB9B6D90577B83BB9%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22trustcentermacro.png%22%20alt%3D%22trustcentermacro.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EUsage%20of%20Excel%204.0%20(XLM)%20macros%20are%20restricted%20by%20default%20through%20the%20Trust%20Center%20Macro%20Settings.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3057905%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExcel%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExcel%204.0%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVBA%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EXLM%20Macros%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3132997%22%20slang%3D%22en-US%22%3ERe%3A%20Excel%204.0%20(XLM)%20macros%20now%20restricted%20by%20default%20for%20customer%20protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3132997%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20John%2C%3C%2FP%3E%0A%3CP%3EFortunately%2C%20the%20Excel%20team%20has%20already%20separated%20XL4%20macros%20from%20VBA%20macros%2C%20not%20only%20can%20they%20be%20managed%20independently%2C%20but%20we've%20recently%20restricted%20them%20by%20default.%3C%2FP%3E%0A%3CP%3ESee%20this%20blog%20post%20for%20more%20information%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexcel-blog%2Fexcel-4-0-xlm-macros-now-restricted-by-default-for-customer%2Fba-p%2F3057905%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexcel-blog%2Fexcel-4-0-xlm-macros-now-restricted-by-default-for-customer%2Fba-p%2F3057905%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎Jan 19 2022 11:41 AM
Updated by: