Security hardening change: Enforce policies for Trusted Documents

  • Home |
  • Security hardening change: Enforce policies for Trusted Documents
Microsoft 365 Curtain Reveal Tech Bulletin Header

From Microsoft Corporation
Technical Bulletin MC302216 · Published Dec 7, 2021

Message Summary

This feature update will change the behavior of Office applications to enforce policies that block active content (ex. macros, ActiveX, DDE) on Trusted Documents. Previously, active content was allowed to run in Trusted Documents even when an IT administrator had set a policy to block it. As part of ongoing Office security hardening, the IT administrator’s choice to block active content will now always take precedence over end-user set trusted documents.

This message is associated with Microsoft 365 Roadmap ID 85574.

When will this happen?

Note: This change is released to Insiders in build 2110.

Current channel: we will begin rolling this out in early February and expect to complete rollout early May.

How will this change affect your organization?

The expected impact is when a user opens a previously trusted file with active content that’s enabled. If there’s a policy set by their IT administrator or a trust center setting blocking the active content, the content will remain blocked.

  • When this happens, we will display a business bar with a “Learn more” button that leads to a link explaining the change in behavior and links to Commercial guidance for IT Administrators.

We have also added a backstage slab for all files containing active content displaying the trust scenario of the file.

  • This backstage notification particularly helps in the situation where the IT administrator has blocked all Trust bar notifications with the policy “Disable all Trust Bar notifications for security issues”.
  • For these impacted users with no business bar notification, they can select File/Info and see the backstage Security Information describing the trust scenario for the file.

What do I need to do to prepare for this change?

You might want to notify your users about this change and update your training and documentation as appropriate.

Learn more:

Recent Comments

No comments to show.

Recent Posts

Microsoft 365 Curtain Reveal Tech Bulletin Header
New Outlook for Windows: Auto-reading emails with Microsoft Windows Narrator
October 14, 2024
Microsoft 365 Curtain Reveal Tech Bulletin Header
(Updated) Microsoft Purview: Minor encrypted message portal design updates, URL to remain the same
October 14, 2024
Microsoft Exchange Curtain Reveal Tech Bulletin Header
(Updated) Microsoft Defender for Office 365: Tenant Allow/Block List will support IPv6 allow and block entries
October 14, 2024