ActiveX Replaced by Microsoft 365
- Microsoft is phasing out ActiveX controls in its Microsoft 365 suite, enhancing security for its users. The change, already implemented for users in the Microsoft 365 Insider program,...
- The initial rollout began in April with build 18730.20030 for Word, Excel, PowerPoint, and Visio on Windows.
- Users who still require ActiveX functionality can manually enable it through the File | Options | Trust Center | trust Center Settings | ActiveX Settings menu.
Microsoft to Disable ActiveX by Default in Microsoft 365
Table of Contents
- Microsoft to Disable ActiveX by Default in Microsoft 365
- Microsoft Disables ActiveX by Default in Microsoft 365: your Questions Answered
Microsoft is phasing out ActiveX controls in its Microsoft 365 suite, enhancing security for its users. The change, already implemented for users in the Microsoft 365 Insider program, will eventually roll out to all users, though a specific timeline has not been announced.
The initial rollout began in April with build 18730.20030 for Word, Excel, PowerPoint, and Visio on Windows. Now, when a file containing an ActiveX control is opened, the request will display a notification that the element has been blocked. Previously, a warning bar appeared with an option to unblock the control.
Manual Activation Still Possible
Users who still require ActiveX functionality can manually enable it through the File | Options | Trust Center | trust Center Settings | ActiveX Settings menu. However, Microsoft recommends keeping ActiveX disabled due to potential security vulnerabilities.
A History of ActiveX
Introduced in 1996,ActiveX expanded upon earlier COM and OLE technologies. It gained prominence through Internet Explorer, enhancing website functionality but also introducing security risks.While ActiveX provided additional features in Office applications, the inherent security concerns remained.
Numerous instances have been documented where malicious elements were embedded within documents via ActiveX controls. Opening such a document could compromise a system. Microsoft addressed one such vulnerability in 2021 (CVE-2021-40444), highlighting the ongoing risks associated with the technology.
ActiveX Use Cases in Office
ActiveX controls were used in Office applications to add interactive elements. for example, an Excel cell might contain a calendar for date selection, or a task list with check boxes. Sliders could also be added to cells for value adjustment.
The move to disable ActiveX by default reflects a broader shift towards more secure and standardized web technologies.
Microsoft Disables ActiveX by Default in Microsoft 365: your Questions Answered
Microsoft is enhancing the security of its Microsoft 365 suite by disabling ActiveX controls by default. This change, which has already begun rolling out, impacts how you interact with certain files and applications. Let’s dive into the details, answering your key questions about this crucial shift.
What is ActiveX and Why is Microsoft Disabling It?
What is ActiveX?
activex is a technology,introduced in 1996,that allows software components to interact within applications like microsoft Office and Internet Explorer. Think of it as a way to add interactive elements, such as calendars or task lists, directly into your documents.
Why is Microsoft disabling ActiveX by default?
The primary reason is security. ActiveX has historically been a point of vulnerability, allowing malicious actors to embed harmful code within files. By disabling it by default, Microsoft is significantly reducing the attack surface and protecting users from potential threats. As the source article mentions, the move to disable ActiveX reflects a shift toward more secure and standardized web technologies.
Has this change already been rolled out?
Yes, it has. The initial rollout started in April with the Microsoft 365 Insider program. Users in the Insider program on Word, Excel, PowerPoint, and Visio for Windows (build 18730.20030 and later) should already notice the change. It’s slowly rolling out to all users.
When will this change affect all Microsoft 365 users?
While the rollout has begun,a specific timeline for all Microsoft 365 users hasn’t been announced as per the article source. Expect it to happen progressively.
How Does the ActiveX default Block Work?
What happens when I open a file with an ActiveX control now?
Instead of a warning bar with an option to unblock the control, you’ll see a notification that the element has been blocked. This is the default behaviour, designed to protect your system.
Can I Still Use ActiveX in Microsoft 365?
Can I still use ActiveX if I really need it?
Yes, manual activation is still possible. Tho,Microsoft strongly recommends keeping ActiveX disabled due to the associated security risks.
How do I manually enable ActiveX?
You can enable ActiveX through the following steps (but remember the security implications!):
- Go to File.
- Select Options.
- Click on Trust Center.
- select Trust Center Settings.
- Navigate to ActiveX Settings.
Where Did ActiveX Come From?
When was ActiveX introduced?
ActiveX was introduced in 1996, building on earlier technologies like COM (Component Object Model) and OLE (Object Linking and Embedding).
What were activex controls used for in Office applications?
ActiveX controls were used to add interactive features.Here are a few examples:
- Calendars for date selection in Excel cells.
- Task lists with checkboxes in Excel.
- Sliders for adjusting values in cells.
What are the security risks associated with ActiveX?
ActiveX’s design allows for the execution of code within documents, which unfortunately makes it susceptible to malicious attacks. Attackers have exploited activex controls to embed harmful elements, potentially compromising a system.
Yes,there have been several documented vulnerabilities.One notable example is CVE-2021-40444, which Microsoft addressed in 2021. This highlights the ongoing risks associated with ActiveX.
A Swift Comparison: ActiveX vs. Modern Alternatives
Here’s a simple comparison to highlight the shift towards more secure technologies:
| Feature | ActiveX | Modern Alternatives |
|---|---|---|
| Security | High risk of vulnerabilities | Enhanced,built-in security and sandboxing |
| Technology | Older,proprietary Microsoft technology | HTML5,JavaScript,WebAssembly (more open and standard) |
| Compatibility | Limited (primarily Internet Explorer and Microsoft Office) | Cross-browser and cross-platform compatibility |
| Maintenance | Difficult to patch and maintain | Easier to update and maintain with security updates |
| User experience | Can provide rich interactivity,but often inconsistent. | More consistent and feature-rich experiences |
By disabling ActiveX by default, Microsoft is taking a proactive step towards a safer and more secure computing environment for its users. While the change may require some users to adjust,the long-term benefits for security are significant.
