"Enable Content": The Macro Warning You Should Never Ignore
A document says "Enable content to view". That yellow bar is one of the most important warnings on your computer. How malicious macros work and why you should refuse.

You open an attachment and see a blurry document with a message: "This document is protected. Click Enable Content to view." A yellow bar at the top offers exactly that button. This is one of the oldest and most effective malware tricks. The document is not protected; clicking lets hidden code run.
How malicious macros work
- An email delivers a Word or Excel file, often an "invoice", "order" or "CV".
- The document opens in Protected View, a safe read-only mode.
- A fake message tells you to click "Enable Editing" and then "Enable Content".
- Once enabled, the macro downloads and runs malware, such as password stealers or tools that lead to ransomware.
The rule
Never click Enable Content on a document you received by email. If you genuinely need a macro-enabled file, confirm with the sender through another channel and ask your IT team.
For organizations
- Block macros in files from the internet, which modern Office versions increasingly do by default.
- Allow macros only from trusted locations or signed publishers.
- Train staff with this exact example.
If you enabled content
Disconnect from the network and contact IT immediately. See opening an attachment by mistake.
Got a document asking you to enable content? Close it and paste the email into CyberWatch AI Scan for a free check.
Related: dangerous email attachments. For more, see how phishing works in our complete guide.
Frequently asked questions
What is a macro?
A small program inside an Office document that automates tasks. Attackers use macros to download and run malware when enabled.
Is 'Enable Editing' the same as 'Enable Content'?
No. Enable Editing leaves Protected View; Enable Content allows macros to run. Both should be avoided for unexpected documents from email.
Do genuine documents need macros?
Some internal business tools do, but documents arriving by email from outside your organization almost never need them.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- Mitigating malware and ransomware attacks, UK National Cyber Security Centre
- Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission


