How to Configure a Trusted Publisher for Excel Macros Using Intune
Question details
The user needs a way to allow users to safely run macro-enabled Excel reports downloaded from Google Drive using Microsoft Intune, without relying on Active Directory.

- Product
- Microsoft Excel, Microsoft Intune
- Device & OS
- Windows
- Scenario
- Users in an organization download macro-enabled Excel reports from Google Drive into their local Downloads folder.
- Observed behavior
- Excel blocks the macros from running because the files originate from the internet and the Downloads folder is not an inherently trusted location.
Ensure you have Microsoft Intune administrator privileges to deploy configurations and possess a valid code-signing certificate to sign your VBA project.
Deploy a Trusted Publisher Certificate via Microsoft Intune
Sign your VBA project with a code-signing certificate and use Microsoft Intune to deploy the certificate to all organizational devices.
This is the recommended enterprise solution for managing macro security in a cloud-only environment without Active Directory. By deploying the certificate to the Trusted Publishers store, Excel will automatically trust macros signed with it, regardless of whether the file is stored in a trusted location like the Downloads folder.
Open your macro-enabled Excel file, press ALT + F11 to open the VBA Editor, go to Tools > Digital Signature, and sign your VBA project using a valid code-signing certificate.
Export the public key of the certificate (as a .cer file) from the machine where the macro was signed using the Windows Certificate Manager (certmgr.msc).
Log in to the Microsoft Endpoint Manager (Intune) admin center with administrator credentials.
Navigate to Devices > Configuration profiles. Click 'Create profile', select 'Windows 10 and later' as the platform, and choose the 'Trusted certificate' template.
Upload your .cer file, set the destination store to 'Trusted Publishers', and assign the profile to your target user groups.

Unblock Individual Macro-Enabled Files Manually
End-users can manually unblock specific Excel files downloaded from the internet to bypass the security block on macros.
Try WPS Office for Seamless Spreadsheet and Macro Management
If navigating complex Microsoft Intune policies to manage Excel macros is slowing down your administrative workflow, consider WPS Office. It provides a lightweight, highly compatible alternative for handling complex spreadsheets and VBA macros with an intuitive interface.
- 1. Download and Install: Download WPS Office from the official website and follow the installation wizard.
- 2. Open the Spreadsheet: Launch WPS Spreadsheets and open your .xlsm file containing the macros.
- 3. Enable Macros: Click 'Enable Macros' in the security warning prompt at the top of the worksheet to safely run your VBA code.

Frequently Asked Questions
Why does Excel block macros in files from the Downloads folder?
Windows applies a 'Mark of the Web' tag to files downloaded from the internet. Excel's default security settings block macros in these files because the Downloads folder is not a trusted location, effectively protecting your system from potentially malicious code.
Can I just add the Downloads folder to Excel's Trusted Locations?
While technically possible, it is highly discouraged. Adding the Downloads folder to your Trusted Locations drastically lowers your system's security. Any malicious file downloaded to that folder would be allowed to execute its macros without security restrictions.
Do I need Active Directory to manage Trusted Publishers for Excel?
No, Active Directory is not strictly required. If your organization uses Microsoft 365 Business Premium and Azure AD, you can use Microsoft Intune to deploy Trusted Publisher certificates directly to cloud-managed Windows devices.




