kennysarmy Posted October 6, 2016 Posted October 6, 2016 With the current high threat of Ransomware I'm debating whether to use a group policy object to block all macros from running. But what are the cons of doing this? What can break if I action this? Regards
3s-gtech Posted October 6, 2016 Posted October 6, 2016 Certain SIMS reports may not run. Certain custom spreadsheets made by departments or users may not run (e.g. custom marksheets) Some returns from LEA or other authorities may use macros. Those are my experiences. I've had to re-open some macro settings to enable our admin staff to run them, but they're still well locked down for teachers and students.
kennysarmy Posted October 6, 2016 Author Posted October 6, 2016 Certain SIMS reports may not run. Certain custom spreadsheets made by departments or users may not run (e.g. custom marksheets) Some returns from LEA or other authorities may use macros. Those are my experiences. I've had to re-open some macro settings to enable our admin staff to run them, but they're still well locked down for teachers and students. Yes I've just tested with SIMS.net Reports that output to Excel and found they would break Is there a way to allow JUST reports that have their origins in SIMS.net or will I be forced to create allow rules for certain staff
Arthur Posted October 6, 2016 Posted October 6, 2016 Yes I've just tested with SIMS.net Reports that output to Excel and found they would break Have you already applied patch 21751? 1
3s-gtech Posted October 6, 2016 Posted October 6, 2016 As Arthur says - that patch means that SIMS macros are now signed - this can help to reduce issues there significantly. We applied this and it helped - but then found that the LEA still fire worksheets with unsigned macros around (usually created in Office 2003, because that's obviously up to date) which we're expected to use.
kennysarmy Posted October 6, 2016 Author Posted October 6, 2016 As Arthur says - that patch means that SIMS macros are now signed - this can help to reduce issues there significantly. We applied this and it helped - but then found that the LEA still fire worksheets with unsigned macros around (usually created in Office 2003, because that's obviously up to date) which we're expected to use. I would think so but will check - it may be that I tried to run an older report! On another issue - is it possible to have trusted network locations for Access Databases that would open without the security warning : Some active content has been disabled click for more details [Enable Content] Ideally I'd like to locate all the network folder locations and ONLY allow those to run Access Macros. I can't quite get my head around the Trusted Location options in Group Policy Management...
kennysarmy Posted October 6, 2016 Author Posted October 6, 2016 Set a network location to be trusted. But the end users still see this message?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now