Skip to content
  • There are no suggestions because the search field is empty.

ACSC E8 Nov 2023-ML2 Restrict Office macros

Overview

The Devicie Essential Eight Maturity Level 2 Restrict Office Macros (Block) (Nov 2023) configuration is to meet the Australian Cyber Security Centre’s guidance for this mitigation strategy.

Intune Description:

E8 ML2 Restrict Office Macros (Block) (Nov 2023)

Scope:

This baseline should be applied to Windows devices. Must be deployed with “DEVICIE-PROD-ACSC E8 Nov 2023-ML1 Restrict Office macros-Block”

Policy Impact Areas:

When deployed, this policy will impact:

  • Blocking when users attempt to use macros, within all Office 365 products

Deployment Notes

  1. Pre-Deployment Considerations:

    • Recommended to utilise “DEVICIE-PROD-ACSC E8 Nov 2023-ML1 Restrict Office macros-Allow with prompt” first, to measure user impact.

    • Consider users who may be impacted by this change (typically finance teams). Note that this is a block policy, so effective communication with user feedback will assist in longer term deployments to higher levels of controls.

  2. Post-Deployment Validation:

    • Attempt to run a macro within Excel

Configuration Settings

 
 

Name

Value

Defender

Attack Surface Reduction Rules

 

  Block Win32 API calls from Office macros

Block

 

Devicie Template Name

ACSC E8 Nov 2023-ML2 Restrict Office macros

Default Intune Deployed Name

DEVICIE-PROD-ACSC E8 Nov 2023-ML2 Restrict Office macros

Version

1.0

Template Last Updated

Jul 8, 2025

Document Last Updated:

Jul 8, 2025