Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

With the current high threat of Ransomware I'm debating whether to use a group policy object to block all macros from running.

 

But what are the cons of doing this?

What can break if I action this?

 

Regards

Posted

Certain SIMS reports may not run.

Certain custom spreadsheets made by departments or users may not run (e.g. custom marksheets)

Some returns from LEA or other authorities may use macros.

 

Those are my experiences. I've had to re-open some macro settings to enable our admin staff to run them, but they're still well locked down for teachers and students.

Posted
Certain SIMS reports may not run.

Certain custom spreadsheets made by departments or users may not run (e.g. custom marksheets)

Some returns from LEA or other authorities may use macros.

 

Those are my experiences. I've had to re-open some macro settings to enable our admin staff to run them, but they're still well locked down for teachers and students.

 

Yes I've just tested with SIMS.net Reports that output to Excel and found they would break :(

 

 

Is there a way to allow JUST reports that have their origins in SIMS.net or will I be forced to create allow rules for certain staff :(

Posted
As Arthur says - that patch means that SIMS macros are now signed - this can help to reduce issues there significantly. We applied this and it helped - but then found that the LEA still fire worksheets with unsigned macros around (usually created in Office 2003, because that's obviously up to date) which we're expected to use.
Posted
As Arthur says - that patch means that SIMS macros are now signed - this can help to reduce issues there significantly. We applied this and it helped - but then found that the LEA still fire worksheets with unsigned macros around (usually created in Office 2003, because that's obviously up to date) which we're expected to use.

 

I would think so but will check - it may be that I tried to run an older report!

 

On another issue - is it possible to have trusted network locations for Access Databases that would open without the security warning : Some active content has been disabled click for more details [Enable Content]

 

Ideally I'd like to locate all the network folder locations and ONLY allow those to run Access Macros.

 

I can't quite get my head around the Trusted Location options in Group Policy Management...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...