Skip to content

Macros and hardening

Macros and browsers locked down, without blocking the people who need them.

Malicious macros and browser exploits are still two of the most common ways in. We block macros except where there is a business need, harden browsers and Office, and give the people who need macros a safe way to keep working.

  • Fixed fee, paid by milestone
  • Microsoft Partner
  • AZ-104 and AZ-305 certified engineers
  • Senior engineers only
  • Brisbane-based, working across Australia
See the full Essential Eight service

How we deliver it

  1. Discovery: which teams use macros, which files and where they come from.
  2. Trusted macros: signed or stored in trusted locations for the teams that need them.
  3. Blocking: macros from the internet blocked, and macros blocked for everyone without a business need.
  4. Office and browser hardening: policies that switch off risky features and old content types.
  5. Attack surface reduction: Defender rules that stop Office and scripts being used to launch malware.
  6. PowerShell: constrained where it isn't needed, and logged where it is.

What you receive

  • Macro, Office and browser settings, recorded and handed over
  • A register of approved macros and their owners
  • Evidence against the macro and user application hardening requirements for your target level

How long it takes

Two to four weeks. It is a fixed fee, paid by milestone.

Questions buyers ask

Our finance team lives in macros. Will this stop them?

No. We find their macros first, then sign them or trust their location, so finance keeps working and everything else is blocked.

Does Business Premium support the macro settings?

Only partly. Microsoft 365 Apps for Business supports a smaller set of policies than Apps for Enterprise. For Maturity Level Two macro controls, we usually recommend Apps for Enterprise for the users in scope.

Start a conversation

Close the most common ways in.

Tell us who relies on macros and your target level.

Talk to an Engineer