Skip to main content

What is Microsoft thinking?!

What is Microsoft thinking?!
TylerM
Administrator
Forum|alt.badge.img+25
  • Sr. Security Analyst & Community Manager
  • 1274 replies

Microsoft rolls back decision to block Office macros by default

By 

Sergiu Gatlan

 

Read the full bleeping computer article here

While Microsoft announced earlier this year that it would block VBA macros on downloaded documents by default, Redmond said on Thursday that it will roll back this change based on "feedback" until further notice.

The company has also failed to explain the reason behind this decision and is yet to publicly inform customers that VBA macros embedded in malicious Office documents will no longer be blocked automatically in Access, Excel, PowerPoint, Visio, and Word.

"Based on feedback, we're rolling back this change from Current Channel," the company notified admins in the Microsoft 365 message center (under MC393185 or MC322553) on Thursday.

"We appreciate the feedback we've received so far, and we're working to make improvements in this experience. We'll provide another update when we're ready to release again to Current Channel. Thank you."

The change began rolling out in Version 2203, starting with Current Channel (Preview) in early April 2022, with general availability to be reached in June 2022, as BleepingComputer previously reported.

This was a welcome and highly expected change, given that VBA macros are a popular method to push a wide range of malware strains (including EmotetTrickBotQbot, and Dridex) via phishing attacks with malicious Office document attachments.

With VBA macros blocked by default, everyone was expecting attacks that delivered malware (such as information-stealing trojans and malicious tools used by ransomware groups) to be automatically thwarted.

On systems where VBA macros aut0blocking is enabled, customers see a "SECURITY RISK: Microsoft has blocked macros from running because the source of this file is untrusted" security alert.

If clicked, the warning sends users to an article containing information about the security risks behind threat actors' use of Office macros and instructions on enabling these macros if absolutely necessary.

Mockup of new Office macros security alert
Mockup of new Office macros security alert (BleepingComputer)

Confused users asking for an explanation, more transparency

Microsoft's customers were the first to notice that Microsoft rolled back this change in the Current Channel on Wednesday, with the old 'Enable Editing' or 'Enable Content' buttons shown at the top of downloaded Office documents with embedded macros.

"Is it just me or have Microsoft rolled this change back on the Current Channel?" one Microsoft Office user asked in the comments of Microsoft's February blog post announcing that VBA macros will be disabled.

"It feels like something has undone this new default behaviour very recently... maybe Microsoft Defender is overruling the block?"

"Based on feedback received, a rollback has started. An update about the rollback is in progress," replied Angela Robertson, a Principal GPM for Identity and Security on the Microsoft 365 Office team.

"I apologize for any inconvenience of the rollback starting before the update about the change was made available."

Another customer complained about Microsoft's "lack of communication" after announcing this change and asked the company to share more info on this rollback "elsewhere."

"Your standard SMB and even mid-sized businesses are going to implode if this gets fully implemented in it's current form," the customer said.

"You seem to be catering to enterprises now that have very large teams of people to manage your products, and that's simply not the case for most of the user base. It needs to be simplified before it's released, and moreso, it needs to be effectively communicated."

"Rolling back a recently implemented change in default behaviour without at least announcing the rollback is about to happen is very poor product management," another added.

 

Did this help you find an answer to your question?

12 replies

TylerM
Administrator
Forum|alt.badge.img+25
  • Author
  • Sr. Security Analyst & Community Manager
  • 1274 replies
  • July 8, 2022

 


quicks
New Voice
  • New Voice
  • 20 replies
  • July 8, 2022

Ah… Microsoft. That beautiful entity that makes me question my will to live.
 

 


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 9116 replies
  • July 9, 2022

My settings have not changed as i set it this way years ago!

 

 


TylerM
Administrator
Forum|alt.badge.img+25
  • Author
  • Sr. Security Analyst & Community Manager
  • 1274 replies
  • July 11, 2022

Microsoft flip flopped back again

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-decision-to-unblock-office-macros-is-temporary/

 

"Following user feedback, we have rolled back this change temporarily while we make some additional changes to enhance usability," explained Kellie Eickmeyer, a principal program manager at Microsoft, in a Friday update to the February announcement.

"This is a temporary change, and we are fully committed to making the default change for all users. We will provide additional details on timeline in the upcoming weeks."


Jamesharris85
New Voice
Forum|alt.badge.img+4

Good old Microsoft 🤣


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • July 18, 2022

I assume someone who pays M$ a lot of money complained...uh….I mean provided “feedback” that they did not like their macros blocked.

Is there any other explanation that makes sense?


AsadP
New Voice
Forum|alt.badge.img+1
  • New Voice
  • 56 replies
  • July 18, 2022

Below is a representation of quality control for updates at Microsoft:
 

Microsoft Office Team Leader: Let’s update MS Office!


MS Employee: yes


tasystems
New Voice
Forum|alt.badge.img+8
  • New Voice
  • 156 replies
  • July 19, 2022

Sometimes you have to wonder who on earth is in charge of Microsoft decision making… What's that saying… “The lunatics are running the asylum” - Seems very appropriate here!


Microsoft be like…

 


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 9116 replies
  • July 21, 2022

More news on this:

Microsoft starts blocking Office macros by default, once again

July 21, 2022

 

https://www.bleepingcomputer.com/news/microsoft/microsoft-starts-blocking-office-macros-by-default-once-again/


TylerM
Administrator
Forum|alt.badge.img+25
  • Author
  • Sr. Security Analyst & Community Manager
  • 1274 replies
  • July 21, 2022
TripleHelix wrote:

More news on this:

Microsoft starts blocking Office macros by default, once again

July 21, 2022

 

https://www.bleepingcomputer.com/news/microsoft/microsoft-starts-blocking-office-macros-by-default-once-again/

waiting for yet another flip flop...


TylerM
Administrator
Forum|alt.badge.img+25
  • Author
  • Sr. Security Analyst & Community Manager
  • 1274 replies
  • July 21, 2022
ashley.horsup wrote:

Microsoft be like…

 

This is the perfect Gif


Reply