Disable macros before opening a file you don't fully trust

Excel macros are small programs that automate repetitive tasks — they can save time when you're working with spreadsheets you created yourself. But macros can also be weaponized. A macro embedded in a spreadsheet someone sends you can steal passwords, install malware, or lock your files for ransom. The safest approach is to disable macros by default and turn them on only for files you know are safe.

Windows and Mac handle this differently, and the steps depend on which version of Excel you're using. The goal is the same: prevent any macro from running unless you explicitly say it's okay.

Key Takeaways

  • Disable macros in Excel settings so they don't run automatically when you open a file.
  • When you open a file with macros, Excel will show a notification bar asking permission — choose "Don't Enable" unless you recognize the file source.
  • If you need a macro to work, enable it only after confirming the file came from someone you trust.
  • Macros are most dangerous in files from strangers or unexpected email attachments, even if they look like normal spreadsheets.

Disable macros in Windows Excel

Open Excel and go to File in the top left. Click Options at the bottom of the left sidebar. In the Options window, click Trust Center on the left side, then click the Trust Center Settings button.

In the Trust Center window, click Macro Settings on the left. You'll see four radio button options. Select Disable all macros without notification. This is the most secure setting — macros won't run at all, and Excel won't ask you about them. If you want Excel to notify you when a file contains macros (so you can choose to enable them), select Disable all macros with notification instead. Click OK twice to save and close.

From now on, any macro in any Excel file will be blocked. If you open a file that contains a macro and you want it to run, you'll need to go back to this same menu and temporarily change the setting, or you can enable macros just for that one file using the notification bar that appears when you open it.

Disable macros in Mac Excel

Open Excel and click Excel in the top menu bar (next to the Apple logo). Click Preferences. In the Preferences window, look for Security & Privacy and click it. You may need to scroll down to find it.

Under the Security section, you'll see macro security options. Select Disable all macros without notification for the strongest protection. If you prefer to be asked about macros each time, choose Disable all macros with notification. Click the close button to save your changes.

What happens when you open a file with macros

If you've set Excel to "Disable all macros with notification," a yellow or blue notification bar will appear at the top of the spreadsheet when you open a file containing macros. It will say something like "Security Warning: Macros have been disabled." There will be a button that says Enable Content or Enable Macros.

Do not click that button unless you're certain the file is safe. Ask yourself: Did I create this file? Did a coworker I trust send it to me? Did I download it from an official source? If the answer to all three is no, leave macros disabled. If you're unsure, contact the person who sent it and ask them to confirm they created it.

When to enable macros for a specific file

You may have spreadsheets you created yourself that use macros, or files from your employer that require macros to work properly. For those files, you have two choices: enable macros just for that one file, or temporarily change your macro security setting.

To enable macros for just one file, click the Enable Content button in the notification bar when you open it. Excel will allow that file's macros to run. The next time you open a different file with macros, you'll be asked again.

If you work with macro-enabled files regularly, you can add them to Excel's Trusted Locations. Go back to File > Options > Trust Center > Trust Center Settings, then click Trusted Locations. Click Add New Location and browse to the folder where you keep your safe files. Any file in that folder will run macros without asking.

Recognize when a file might contain hidden macros

Macros are most commonly found in files with these extensions: .xlsm (Excel Macro-Enabled Workbook), .xls (older Excel format), and .xlam (Excel Add-in). Files ending in .xlsx (the standard modern format) should not contain macros, though they technically can in rare cases.

Be especially cautious of spreadsheet files that arrive as email attachments, particularly from people you don't know or from unexpected sources. Criminals often disguise malware as invoices, timesheets, or financial reports. If someone sends you a spreadsheet and you weren't expecting it, contact them through a separate channel (a phone call or a message through your company system) to confirm they sent it before you open it.

Frequently Asked Questions

Will disabling macros break my spreadsheets?

No. Disabling macros only prevents the automated code from running. Your data, formulas, and formatting will all work normally. You'll just lose the automation that macros provide — things like buttons that fill in data or calculations that run automatically.

Can I disable macros for some files but not others?

Yes. Set your default to "Disable all macros with notification," then use the notification bar to enable macros only for files you trust. Alternatively, add trusted folders to your Trusted Locations list so macros run automatically only in those folders.

What if I need to send a macro-enabled file to someone else?

Save it with the .xlsm extension so they know it contains macros. Let them know what the macros do and why they're necessary. They can then decide whether to enable them based on whether they trust you and your file.

Does disabling macros protect me from all spreadsheet threats?

Macros are one common attack vector, but not the only one. Disabling them removes a major risk, but you should still be cautious about opening unexpected files from unknown sources and keep your Excel software updated.