Microsoft Office macros remain a persistent delivery mechanism for malicious code, which is why the Australian Cyber Security Centre lists configuring macro settings among the Essential Eight mitigation strategies. For organisations in government, aged care, and enterprise, the challenge is no longer deciding whether to restrict macros, but enforcing those restrictions consistently across a device fleet that increasingly mixes on-premises, hybrid, and cloud-managed endpoints.
Legacy Group Policy still works for domain-joined machines, but it does not reach devices that are Azure AD joined, Intune managed, or used by staff who rarely touch the corporate network. Cloud Policy, delivered through the Microsoft 365 Apps admin centre, offers a user-centric alternative that applies macro controls wherever a licensed user signs in to the Office desktop applications.
The macro control within the Essential Eight focuses on reducing the attack surface presented by Visual Basic for Applications. At a foundational level, the guidance directs organisations to block macros in files that originate from the internet, to allow only macros that are digitally signed by a trusted publisher or that run from vetted trusted locations, and to prevent users from changing these settings themselves.
As maturity increases, the expectations tighten. Higher maturity levels call for macro execution to be limited to a documented business need, for antivirus scanning of macro-enabled content, and for logging of macro activity so that unusual behaviour can be investigated. Translating those principles into concrete configuration is where administrators need a reliable, centrally managed control plane.
Cloud Policy is accessed through the Microsoft 365 Apps admin centre. Rather than editing registry keys or deploying ADMX templates, administrators create a policy configuration, assign it to an Azure AD security group, and select the specific settings to enforce. The policy applies the next time an affected user signs in to an Office application, and it re-evaluates at each launch, which means the setting cannot be permanently overridden on the device.
The most relevant settings for macro hardening include the following.
Because Cloud Policy assigns settings to users rather than machines, a finance officer who works from a managed laptop, a shared desktop, and a Windows 365 Cloud PC receives the same macro posture on every device. This consistency is difficult to achieve when policy depends on device domain membership alone.
Trusted locations deserve careful attention. A trusted location is only as safe as the permissions applied to it. Directories that any user can write to undermine the control entirely, so these paths should be restricted to a small set of accounts and reviewed regularly. Where possible, prefer digitally signed macros over expanding trusted locations, because signatures tie execution to a verifiable publisher.
Change management also matters. Before enforcing signed-only or internet-blocking policies broadly, identify the line-of-business documents that rely on macros. A pilot group scoped through an Azure AD security group allows administrators to observe impact and adjust before wider rollout. Cloud Policy makes staged deployment straightforward because assignment is group based.
Finally, macro configuration should not stand alone. Pair it with attack surface reduction rules in Microsoft Defender, centralised logging, and antivirus scanning of macro-enabled files to align with the higher maturity expectations. Enforcement without monitoring provides limited assurance, and audit-ready evidence is often as important to regulators as the control itself.
Cloud Policy does not replace every function of Group Policy or Intune, and organisations with mature endpoint management may combine approaches. For macro hardening specifically, however, it provides a scalable, user-centric method that suits hybrid and cloud-managed environments and helps regulated organisations demonstrate consistent alignment with the Essential Eight.

Level 7, 12 St Georges Tce
Perth WA 6000
[email protected]
Ph 1300 NOVATA

In the spirit of reconciliation Novata Solutions acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today. This land always was, and always will be Aboriginal Land.

Novata Solutions is committed to embracing diversity and eliminating all forms of discrimination through education. We welcomes all people and is respectful of individual identities.