A family of Microsoft spreadsheet software with tools for analyzing, charting, and communicating data
If the site is already in Trusted Sites and downloaded Excel files still show Security Risk with macros blocked, check these points:
- Verify the file is being downloaded from the trusted domain actually added to Windows
- For files downloaded from OneDrive or SharePoint, whether the browser applies Mark of the Web depends on the Windows internet security zone configuration.
- Admins can place the exact SharePoint or OneDrive domain into Trusted Sites by using the Site to Zone Assignment List policy.
- If the file is coming from a different host, subdomain, redirect, or CDN than the one added, the trusted site entry won’t apply.
- Confirm the site is listed in Windows Internet Options
- Go to Control Panel > Internet Options > Change security settings.
- Check whether the website appears under Trusted sites.
- If adding
http://URLs or network shares, clear Require server verification (https:) for all sites in this zone.
- Use Trusted Sites rather than Local intranet when possible
- Trusted Sites is the recommended approach because it has additional security compared to Local intranet.
- If users are accessing a share by IP address, macros remain blocked unless that location is in Trusted sites or Local intranet.
- Check how the file is opened
- If the file is stored on OneDrive or SharePoint, using Open in Desktop App avoids Mark of the Web.
- If the OneDrive sync client downloads the file, the file also won’t have Mark of the Web.
- Downloading through a web browser can still result in Mark of the Web being applied, depending on the zone configuration.
- If the file is downloaded locally, test whether it still has Mark of the Web
- Right-click the file in File Explorer > Properties.
- If Unblock appears on the General tab, the file still has Mark of the Web.
- That means the trusted-site configuration did not match the actual download source or did not apply as expected.
- For a repeatable process, use one of these supported approaches instead of unblocking each file manually
- Have users open the file with Open in Desktop App if the files are on OneDrive or SharePoint.
- Save the files to a Trusted Location.
- Use a trusted site configuration for the exact source location.
- For groups that regularly use these files, admins can assign the SharePoint or OneDrive domain to Trusted Sites with policy.
- Be careful with broad trust settings
- Adding a site to Trusted Sites means files downloaded from that domain can bypass the default macro block.
- Access control on that site still matters, because anyone allowed to upload files there could add files with active content such as macros.
If the goal is to avoid per-file unblocking for another person, the most reliable supported options are:
- Open in Desktop App for files hosted in OneDrive or SharePoint
- Trusted Location for local folders
- Trusted Sites configured for the exact file-hosting domain
References: