Skip to main content

πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“βš™οΈGroup - Unsigned Macros Allowed users

What this group is for​

This is a static assigned user group that carves an exception out of the macro signing baseline for Microsoft 365 Apps.

It works only as a pair with:

Both assignments are required. The baseline writes Trust Center values into HKCU\Software\Policies\Microsoft\Office\16.0\<app>\security, and those values stay written when a user leaves the profile's scope.

This is a user group, not a device group, because Office Trust Center settings live in the user hive. An exempted user carries the weakened Trust Center to every machine they sign in to, shared devices included.

πŸ› οΈ Group Configuration​

SettingValue
Group nameπŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“βš™οΈGroup - Unsigned Macros Allowed users
Group descriptionUsers temporarily exempted from the macro signing baseline while a named business-critical macro is signed. Membership requires a named file, an approver and an end date.
Group typeSecurity
Membership typeAssigned (User Group)

⚠️ Governance​

This group hands a user back the Enable Content button, which is the exact button two decades of malware has been built around. Treat membership as temporary by default:

  • A named file or application, not a job title or a department.
  • A named approver on the customer side.
  • An end date, and a plan for what happens before it: signing the macro, replacing it, or retiring it.
  • A quarterly review that actually removes people.

Good reason: a month-end workbook nobody can sign until the original author's certificate is replaced. Bad reason: "finance uses a lot of spreadsheets." The right destination for almost every member of this group is a signed macro and a removal from the group, not permanent residence.


Every member of this group should have a date on which they stop being one. πŸ”“