Upcoming Microsoft 365 security enhancement: ActiveX controls to be blocked
As part of our ongoing efforts to align with Microsoft's recommended security baselines, ICTS will implement a change to Microsoft 365 applications on 2 November 2026. The change will block ActiveX controls from running within Office documents.
ActiveX controls are an older Microsoft technology used to add interactive functionality to documents. While they were commonly used in legacy Microsoft Office files, they now present a security risk because they can potentially be exploited by malicious actors to execute harmful code.
What does this mean for you?
For most people, this change will have no impact on day-to-day work. However, if you regularly use older Excel, Word, or other Office documents that contain ActiveX controls, some functionality within those documents may no longer work as expected after the change is implemented. These include
- buttons used to trigger actions in spreadsheets
- interactive form fields
- legacy document automation features
What should you do?
ICTS will work with document owners and departments to identify suitable alternatives where required. In many cases, existing ActiveX controls can be replaced with more modern and secure Office features.
If you encounter any issues with Microsoft Office files from 3 November 2026, please log a call with the IT Helpdesk.