How Administrators Can Disable Developer Tools and Macros in Microsoft 365
Question details
An organization needs to restrict employees from creating or running Excel macros and accessing VBA tools for risk management purposes.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Securing an organizational environment by preventing unauthorized macro execution and restricting access to the Developer tab.
- Observed behavior
- Administrators require a centralized method to block macros and disable developer tools across the organization's Microsoft 365 deployment.
Ensure you have global administrator or security administrator privileges in your Microsoft 365 tenant before attempting to modify organizational policies.
Enforce Macro Restrictions via Microsoft 365 Policies
Enterprise administrators can use Microsoft 365 Cloud Policy or Group Policy to enforce macro restrictions globally across all employee devices.
By default, Microsoft has started blocking VBA macros obtained from the internet in Office apps. However, for strict internal compliance, administrators can deploy custom policies to disable VBA entirely or block specific macro functionalities.
Log in to the Microsoft 365 Apps admin center and navigate to Customization > Policy Management.
Click on 'Create' to configure a new policy. Specify a name for the policy and select the scope of users or Azure AD groups you want to apply the restriction to.
In the policies list, search for 'VBA' or 'Macros'. Configure the relevant settings, such as enabling 'Block macros from running in Office files from the Internet' or 'Disable VBA for Office applications'.
Save the policy configuration. The restrictions will take effect on users' devices upon their next policy refresh cycle.

How to Manage Macro Security in WPS Office
If you need to control macro execution to protect your workspace from malicious scripts, WPS Office provides robust, built-in macro security settings that allow you to easily restrict or disable VBA macros.
- 1. Open WPS Spreadsheets: Launch WPS Spreadsheets and open any blank or existing workbook.
- 2. Access the Options Menu: Click on the 'Menu' button located in the top left corner of the application window, then select 'Options' from the drop-down list.
- 3. Navigate to Security Settings: In the Options dialog box, select 'Security' from the left-hand navigation pane.
- 4. Adjust Macro Security Level: Click on 'Macro Security' and choose 'High' or 'Very High' to disable unsigned macros entirely or block all macros from running.
- 5. Save Your Preferences: Click 'OK' to apply your new security settings and protect your workspace.

Frequently Asked Questions
Are macros from the internet blocked by default in Microsoft 365?
Yes, Microsoft has updated its default security settings to block macros in files downloaded from the internet (files with a Mark of the Web) to improve security against malware.
Can I disable macros for specific departments rather than the whole company?
Yes. By using Microsoft 365 Cloud Policies or Group Policy, administrators can target specific Active Directory groups or organizational units, allowing you to restrict macros only for departments that do not require them.
How can a user manually hide the Developer tab in Excel?
A user can right-click anywhere on the Excel ribbon, select 'Customize the Ribbon', and uncheck the 'Developer' option in the right-hand pane to hide the tab from their workspace.




