Launch beta — ExcelifyXML just opened! Feedback, a bug, an idea? Tell us — we read everything.
Skip to main content
← All guides

6 min read

"Microsoft has blocked macros from running": unblock an Excel file safely

You open a downloaded workbook and a red banner says "SECURITY RISK Microsoft has blocked macros from running because the source of this file is untrusted.", with no button to enable content. Here's where this block comes from, and how to unblock a file you're sure about — without lowering your guard for all the others.

Where does this message come from?

VBA macros are a common way to spread malware. Since 2022, Excel therefore blocks macros by default in files that come from the Internet: email attachments, browser downloads… Windows adds a "Mark of the Web" to these files, and Excel refuses to run their macros.

This block only affects Excel on Windows: Microsoft states that it doesn't apply on Mac, on iPad or to Excel for the web. On Mac, Excel simply asks at every opening whether you want to enable macros (see below).

Which banner do you see?

  • "PROTECTED VIEW", with an "Enable Editing" button: the file comes from the Internet and opens read-only. Click "Enable Editing"; if the red banner then shows up, follow the steps below.
  • Red "SECURITY RISK" banner, with no button: that's the block on macros in files from the Internet. It goes away once you unblock the file, as explained below.
  • Yellow "SECURITY WARNING Macros have been disabled" bar, with an "Enable Content" button: click it if you're sure about the file. Excel remembers it for that file, as long as you don't move it.
  • "Your administrator has restricted the use of macros in your organization": that's a rule set by your company (see "At work").

Before unblocking: are you sure where it comes from?

  • You were expecting this file and know where it comes from — for instance a workbook you've just generated yourself on a site you trust: you can unblock it.
  • Unexpected attachment, "urgent" invoice, unknown sender: don't unblock, delete the file.
  • If in doubt, ask your IT department.

Unblock one specific file (Windows)

  1. Close the workbook in Excel.
  2. In File Explorer, right-click the file, then choose Properties (or select the file and press Alt+Enter).
  3. At the bottom of the General tab, under "This file came from another computer…", tick the "Unblock" checkbox, then click OK.
  4. Reopen the workbook. If Excel shows the yellow "Enable Content" bar, click it.

Special cases

  • The file is inside a ZIP: unblock the .zip file before extracting it, as files extracted with Windows File Explorer inherit the Mark of the Web. And don't open the workbook straight from inside the ZIP: extract it first.
  • There's no "Unblock" checkbox: if the file is on a network share, Windows may treat it as coming from the Internet without offering to unblock it. Copy it to a folder on your computer and open the copy. If the checkbox is also missing for a file on your computer, your organization has hidden it: it's up to your IT department.
  • OneDrive, SharePoint or Teams files: a file opened with "Open in Desktop App", or synced by the OneDrive app, doesn't carry the Mark of the Web; a file downloaded with the browser does. And Excel for the web doesn't run any macro anyway.
  • You prefer the command line: in PowerShell, Unblock-File -Path "C:\Users\you\Downloads\workbook.xlsm" does the same as the "Unblock" checkbox.
  • Nothing works: your organization may have forbidden macros. It's then up to your IT department to decide.

What about Mac?

Excel for Mac doesn't apply this block. Every time you open a workbook that contains macros, it asks "Do you want to disable macros before opening the file?": click "Enable Macros" if you're sure about the file.

No question when opening? Excel is set to disable macros without warning. In Excel › Preferences (or Settings) › Security, choose "Disable all macros with notification", the default setting — don't enable all macros. If the option is greyed out, your organization manages it.

What not to do

  • Don't enable all macros in Excel's settings (Trust Center): Microsoft advises against it, because this setting would expose your computer to every file, not just this one.
  • Don't add your Downloads folder to the trusted locations: any file landing there could run its macros unchecked.
  • Don't bulk-unblock a whole folder of downloaded files: only unblock the file whose origin you know.

At work

Your organization may have tightened these rules. The security settings Microsoft recommends to companies, for instance, only allow digitally signed macros, with no message at all for the others. Unblocking the file is then not enough, and it's up to your IT department: they can review the macro's code, define a trusted location reserved for certain files, or trust the publisher of a signed macro. Microsoft recommends granting such exceptions sparingly.

What about ExcelifyXML workbooks?

Our standalone Excel workbooks contain a macro that does one thing only: read the data sheet and write the XML file where you choose, with no network connection and no automatic start. Its full code is published. It isn't digitally signed yet: if your organization only allows signed macros, use the standard bundle included in every generation, which rebuilds online without macros.

Need to edit an XML file in Excel? Generate a ready-to-use workbook:

Generate my workbook