Policy
Only trust VBA macros that use V3 signatures
Microsoft Office
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10
This policy setting controls whether only VBA macros that use V3 signatures can be trusted and run in the application. If you enable this policy setting, only VBA macros that use V3 signatures can be trusted and run in the application. If you enable this policy setting, we also recommend that you enable the “VBA Macro Notification Settings” policy setting for the application and then select the “Disable all except digitally signed macros” option. Note: Before enabling this policy setting, you should upgrade your existing VBA macros to use V3 signatures. If you disable or don’t configure this policy setting, VBA macros signed with legacy signature schemes can be trusted and run in the application.
Registry values
How enabled and disabled states update the registry.
| Scope | Registry location | Type | Enabled value | Disabled value | Copy |
|---|---|---|---|---|---|
| User | Path software\policies\microsoft\vba\security Value name onlytrustvbasignaturev3 | REG_DWORD | HKCU 1 | HKCU 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.