Why 365 Business Premium Falls Short on Essential 8 Level 2

Macros in Microsoft Office have long been exploited as an entry point for cyber attacks. That’s why the Australian Cyber Security Centre (ACSC) includes them in the Essential Eight Maturity Model. At Maturity Level 2, you’re expected to not just block macros in risky situations, but also prevent users from changing those settings.
The problem is, a lot of organisations think they’re covered because they’ve licensed Microsoft 365 Business Premium. It includes Intune, conditional access, and device compliance, so it seems like it should be enough. But it isn’t.
To meet Level 2, you need more than just Intune and mobile device management. You need enterprise-level licensing, specifically Microsoft 365 Apps for Enterprise, to actually enforce macro settings and prevent users from modifying them.
What Essential Eight Level 2 Requires for Macros
According to the ACSC’s official guidance on restricting Microsoft Office macros at Maturity Level Two, you must have the following in place:
- Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
- Microsoft Office macros in files originating from the internet are blocked.
- Microsoft Office macro antivirus scanning is enabled.
- Microsoft Office macros are blocked from making Win32 API calls.
- Microsoft Office macro security settings cannot be changed by users.
So this isn’t just about switching macros off. You also need to harden the apps so users can’t re-enable macros or modify settings that would reduce protection.
What You Need Technically to Apply These Controls
Microsoft gives you the tools to apply these settings, but only if you’re licensed properly. Here’s what you need:
- Microsoft Intune – to push device configuration and administrative templates. (Explore our IT support services)
- Microsoft 365 Apps for Enterprise – the version of Office that supports full policy enforcement.
- Cloud Policy Service for Microsoft 365 – to centrally manage macro settings that roam with the user.
- Security Baselines – like the Microsoft 365 Apps for Enterprise baseline that includes many recommended macro restrictions.
These tools let you configure things like:
- Blocking macros from internet files
- Preventing changes to macro settings
- Disabling trusted locations and documents
- Enabling macro antivirus scanning
- Blocking Win32 API access from VBA
But here’s the catch: these settings don’t apply correctly if the user has Microsoft 365 Apps for Business instead of Apps for Enterprise.
Why Business Premium Doesn’t Cut It
Microsoft 365 Business Premium comes with a lot, Azure AD Premium P1, Intune, and Microsoft 365 Apps for Business. But that last part is where it breaks down.
This matters because:
- Apps for Business doesn’t support all Group Policy or cloud policy settings.
- Some macro policies may apply initially, but revert after a reboot.
- Users may still be able to access and change macro settings in the Trust Center.
- You can create the policies in Intune, but they won’t actually apply to the Office apps.
There are documented cases where the settings appear to apply, they show as greyed out or enforced, but after restarting Office or the device, they disappear. If you’re audited, this won’t pass. It looks compliant on the surface, but it isn’t.
What Licences Actually Work
To properly enforce macro security settings, users need to be licensed for:
- Microsoft 365 E3 or E5, or
- Office 365 E3 or E5, or
- Microsoft 365 Apps for Enterprise (standalone), or
- Any other bundle that includes Apps for Enterprise
These versions of Office support:
- Full policy enforcement through Intune or Cloud Policy
- Device-based and user-based controls
- Roaming policy support
- Locking down Trust Center settings
- Blocking users from changing any macro configuration
How to Get Compliant
- Audit Your Current Licensing
Check who has Microsoft 365 Business Premium and whether they’re using Apps for Business. Run a licensing report to confirm. - Upgrade to Apps for Enterprise
Where required, assign Microsoft 365 E3, E5, or Apps for Enterprise. These plans allow you to apply and enforce the right policies. - Use Cloud Policy Service or Intune
Go to config.office.com or the Microsoft 365 admin portal. Create a policy for Office apps that applies to your enterprise-licensed users. Use administrative templates in Intune to block macros and lock down settings. - Configure the Right Policies
Set:- Block macros in files from the internet
- Disable all macros except digitally signed (or disable all macros if no business case)
- Prevent users from accessing macro settings in the Trust Center
- Block trusted locations from being added or edited
- Enable antivirus scanning for macros
- Block Win32 API calls in macros
- Test Enforcement
Open a macro-enabled document from the internet. Verify that it doesn’t run and can’t be enabled. Check that macro settings are greyed out in the Trust Center. Reboot and confirm the policy still applies. - Document and Monitor
Record who has a legitimate macro requirement and why. Review policies quarterly. Log macro execution attempts. Ensure all users are covered under enterprise licensing.
What Happens If You Don’t Get It Right
If you rely on Business Premium:
- You’ll appear compliant in Intune, but the policies won’t apply correctly
- Users may be able to change settings and enable macros
- During an audit, you’ll fail Level 2 for macro configuration
- You expose your organisation to malware and phishing attacks that macros are known for
Microsoft 365 Business Premium is a great all-rounder, but it doesn’t go far enough when it comes to locking down macros to Essential Eight Level 2.
To do it right, you need enterprise-grade Office apps, Microsoft 365 Apps for Enterprise, and the policy controls that come with it.
If your organisation is aiming for Level 2 compliance, make sure your licensing reflects that. Otherwise, you’ll be investing time in policies that never truly take effect, and that’s a risk not worth taking.
Contact us if you’d like help with audits, licensing, or implementing secure Office settings.



