Local Tech Fix (626) 655-0020
All articles

Word or Excel Won't Let You Edit a File From Email? What the Yellow and Red Bars Actually Mean

October 9, 2026

Four separate warnings get treated online as one problem, and the most popular fix — switching the warnings off — is how a small office ends up with ransomware.

Google chrome sign-in screen with email field
Photo by Zulfugar Karimov on Unsplash

A supplier emails the updated price list. An insurance broker sends a form. The bookkeeper sends the timesheet template that has run the payroll for nine years. The file opens, you can read every cell of it, and you cannot change a thing — or the buttons that are supposed to do the work do nothing at all, above a bar saying macros have been blocked.

Search for the fix and the first page is remarkably consistent: turn the protection off. Uncheck the Protected View boxes. Set macro security to enable everything. Several of the results are from companies selling spreadsheet-recovery or password-removal tools, which tells you something about who writes this advice and what they want you to download next.

That instinct is wrong, and not for abstract reasons. Office is showing you one of four different mechanisms, each with a different cause and a different correct fix, and the exact words in the bar tell you which one you have hit. Three of them you can clear on a single file in about twenty seconds. The fourth one you should sometimes not clear at all, because it is the protection that stands between a small office and one of the most durable ways ransomware gets into one.

This is the part worth having in writing. The broad fixes that the search results recommend do not fix the file in front of you in most of these cases, and they do lower the floor for every file that arrives afterwards.

Four different warnings, routinely treated as one

Before changing any setting, work out which of these you are looking at. All four can land on the same spreadsheet from the same email.

Protected View. The file opens read-only with a yellow bar, because it came from the internet, from an email attachment, from a folder Windows considers unsafe, or from somebody else's OneDrive. There is an Enable Editing button. This is the common one.

A file-validation failure. The bar is red and the file did not pass Office's structural check. There is no Enable Editing button on the bar; the route is File and then Edit Anyway.

File Block. The file is an old format — a 1990s Word or Excel document — and Office has been configured to open those read-only. Enable Editing is visible but greyed out, by design, and the lever is in a different part of the Trust Center entirely.

The macro block. The bar says Microsoft has blocked macros from running, and this one has no Enable content button at all. This is the one that sends people hunting through Trust Center settings, and the one where the popular advice is actively harmful.

The diagnosis is free: read the bar word for word. Microsoft publishes a distinct sentence for nearly every cause, which makes the banner text the most reliable triage tool on the screen.

The yellow bar: Protected View, and why the file arrived read-only

Microsoft describes Protected View as "a read-only mode where most editing functions are disabled", and lists the reasons a file lands in it. The wording of the bar maps to the reason, so it is worth knowing which sentence means what.

If it says "Be careful - files from the Internet can contain viruses. Unless you need to edit, it's safer to stay in Protected View.", the file came from an internet location. If it says "Be careful - email attachments can contain viruses. Unless you need to edit, it's safer to stay in Protected View.", it arrived as an Outlook attachment from a sender your computer's policy treats as unsafe. If it says "This file was opened from a potentially unsafe location. Click for more details.", it is sitting in a folder Office distrusts — Microsoft's own example is the Temporary Internet Files folder, which is where a file often ends up when you open it straight out of an email instead of saving it first.

There is a fourth one that surprises people in shared offices: "Be careful - This file is from someone else's OneDrive. Unless you trust this person and want to continue collaborating with them, it is safer to stay in Protected View." That one comes with a Trust Documents From This Person option, and it is worth understanding what you are agreeing to. Microsoft's note is explicit: once you click it, "all subsequent documents shared from this OneDrive location will no longer open in Protected View." You are not trusting the file. You are trusting a location, in advance, for everything it sends you later.

When the bar is yellow and you have satisfied yourself the file is genuine, the fix is the button on the bar: Enable Editing. One detail to carry with you — Microsoft notes that after you leave Protected View "the file becomes a trusted document", so that decision has a memory. It is not a one-time peek. Microsoft documents a way to revoke trust from documents you previously trusted, which is the right move if you cleared a file in a hurry and thought better of it afterwards.

The red bar is a different bar, and Enable Editing is not the button

If the message reads "Microsoft 365 has detected a problem with this file. Editing it may harm your computer. Click for more details.", the file failed file validation — Office's scan for "security problems that can result from changes in the file structure". People get stuck here because they are looking for the Enable Editing button they read about, and for the red bar that is not where Microsoft points you. Microsoft's route for the red Message Bar is to select File and then Edit Anyway.

The useful thing to know is which files set this off. Microsoft lists the file types that cause validation errors and they are all the pre-2007 formats: Word 97-2003 files such as .doc and .dot, the Excel 97-2003 family including .xls and .xlt, and PowerPoint 97-2003 files such as .ppt and .pot. If your office still exchanges .xls files with an old accountant or an old piece of industry software, this warning is going to be a regular visitor.

A validation warning is not proof of an attack, and it is not proof of safety either. Microsoft's own list of causes runs both ways: it "can appear for a malicious file, which was created by a hacker", and it can appear because the disk the file lives on "could be worn out or broken", because the file "was created or edited with a program that has a problem", because "an unexpected error occurred while copying the file to your computer" over a flaky connection, or simply because — in Microsoft's words — "there could be a problem with how Microsoft 365 looks for problems in files. We work to make it better, but it's not perfect."

So treat it as what it is: a reason to check the file's provenance rather than a verdict. If a file that has opened cleanly for years suddenly fails validation, the thing we check first is not the sender but the drive it is stored on, because "worn out or broken" is on Microsoft's list for a reason.

“Enable Editing” is greyed out — that is a setting, not a fault

This is the one that wastes the most time, because the button is right there and refuses to work, so it reads as a bug. It is not. It is File Block, a separate list in the Trust Center that governs old file formats.

Microsoft's description: "When you try to open file types created in previous versions of Office (like a Word 95 document), the file will open in Protected View by default and the editing functions will be disabled." There are three possible states, and the middle one is the one that greys out the button. "Do not open selected file types" means the file does not open at all and you get an error. "Open selected file types in Protected View" means, in Microsoft's words, "The Enable Editing button is disabled on the Message Bar and in the Backstage view." The third, "Open selected file types in Protected View and allow editing", is the one that gives you the button back.

There is also a quick visual tell that saves a lot of guessing: "The yellow shield indicates the file can be edited, and the red shield indicates the file can't be edited."

If you need to edit one of these, the path is File, then Options, then Trust Center, Trust Center Settings, and File Block Settings, where you change that file type to "Open selected file types in Protected View and allow editing". One quirk to expect while you are in there, straight from Microsoft: "You can't check Open without checking Save."

Two caveats before anyone goes clicking. First, the reason this list exists is not arbitrary — Microsoft's explanation is that "the code used to open and save the older formats have vulnerabilities that hackers can exploit", so unblocking a format permanently is a real, if small, trade. Second, if you are on an office network, "your administrator might have set policy that doesn't allow you to edit files that are blocked", and no amount of clicking in the Trust Center will override that. Separately, if you cannot leave Protected View at all, Microsoft's answer is the same: "it's possible that your systems administrator has rules established that prevent leaving Protected View."

Our practical advice for a single ancient file: unblock the format, open it, immediately save a copy as .xlsx or .docx, and put the setting back. You end the day with a file that will never trip this again, instead of a permanently loosened setting you will have forgotten about in a year.

“Microsoft has blocked macros from running” is the one you cannot click past

If the bar reads "Microsoft has blocked macros from running because the source of the file is untrusted.", you have met a different mechanism with a deliberately different design. Microsoft calls it the Security Risk banner and documents the key point plainly: "This SECURITY RISK banner doesn't have the option to Enable content." There is a Learn More button and that is it.

That missing button is the whole reason this error generates so much bad advice. Every other Office warning in twenty years has had a button that lets you through, so when this one does not, people assume they are looking at the wrong screen and go digging in the Trust Center until they find Macro Settings and the option to enable all macros. That change does not unblock the file in front of them — the macro security level is not what this block is keyed to, and changing it does nothing to the tag on the file that caused it — and it does remove the warning for every macro file that arrives afterwards. It is the worst of both outcomes: the problem stays and the protection goes.

Microsoft is unusually direct about why the default exists: "VBA macros are a common way for malicious actors to gain access to deploy malware and ransomware." For a small business, that is not a theoretical risk. A macro-enabled attachment that looks like an invoice is one of the oldest and most durable ways into an office network, precisely because invoices are things people are paid to open.

If you remember this working differently, you are not imagining it. Microsoft's own rollout table puts the change in Current Channel with Version 2206, starting to roll out on July 27, 2022, with the other update channels following into 2023. Before that, Microsoft's description of the old behaviour was that a file with Mark of the Web raised a Security Warning banner — one that did have an Enable content button on it.

Who blocked it: the wording tells you, and most of the search results get this wrong

A popular claim about this error is that the missing Enable content button means your IT administrator has locked things down. Usually that is not what happened, and Microsoft publishes different sentences for the two cases, which makes it easy to check.

If the block came from Microsoft's default behaviour, the wording is the one above: "Microsoft has blocked macros from running because the source of the file is untrusted." No administrator is involved. Microsoft's own policy table shows that with the relevant policy left at Not Configured, the result is "Users are blocked from running macros in files obtained from the internet" and "Users see the Security Risk banner with a Learn More button". That is simply how Office ships.

If an administrator did it, you see something else. Microsoft documents "Your administrator has restricted the use of macros in your organization." when opening the file, and "Macros are blocked from this location" when saving it. The remedy is different too: Microsoft's guidance there is to put the file somewhere the administrator has approved, such as OneDrive, rather than to change anything on your own machine.

This distinction matters practically. An office with no administrator and no policy at all can still hit the macro block, because the trigger is where the file came from rather than something somebody configured — so if the wording names Microsoft rather than your administrator, there is no policy to go and ask about.

Mark of the Web: the invisible tag that drives all of this

Behind the macro block sits a small piece of hidden data called Mark of the Web. Microsoft's definition: it "is added by Windows to files from an untrusted location, such as the internet or Restricted Zone. For example, browser downloads or email attachments." The tag travels with the file, which is why a spreadsheet can be blocked on your desk three weeks after it was downloaded.

You can look at the tag yourself, and this is the single most clarifying check in this whole area. At a command prompt, run notepad followed by the file name, a colon and Zone.Identifier — Microsoft gives the command as notepad {name of file}:Zone.Identifier — and Notepad opens showing a ZoneId under a [ZoneTransfer] heading. The values are documented: 0 is My Computer, 1 is Local intranet, 2 is Trusted sites, 3 is Internet, 4 is Restricted sites. Microsoft spells out the consequence: "if the ZoneId is 2, VBA macros in that file won't be blocked by default. But if the ZoneId is 3, macros in that file will be blocked by default."

Now the detail that explains a bad habit we see in small offices. Microsoft notes that "Mark of the Web only applies to files saved on an NTFS file system, not files saved to FAT32 formatted devices." Older and smaller USB sticks are frequently FAT32. So copying a blocked file onto a thumb drive and back can strip the tag, and the macros then run — which looks like a clever workaround and is actually the protection being silently deleted by a file system that cannot store it. If somebody in your office has learned that trick, they have learned to disarm the warning without ever evaluating the file.

One more trap, for offices with a file server: "Even if the Unblock checkbox is available for a file on a network share, selecting the checkbox won't have any effect if the share is considered to be in the Internet zone." If unblocking appears to do nothing on a shared drive, that is usually why, and the fix belongs with whoever configured the share.

The narrow fix, for one file you have actually verified

Assume you have checked the file's provenance — the next section is about how — and you genuinely need its macros. The correct fix is per-file and takes seconds.

Close the file and the Office app. In File Explorer, right-click the file and choose Properties. At the bottom of the General tab, tick the Unblock checkbox and select OK. Reopen the file. That removes Mark of the Web from that one file and leaves every other file on the machine protected exactly as before.

If you prefer the keyboard, Microsoft documents the PowerShell equivalent, the Unblock-File cmdlet, and confirms it "does the same thing as selecting the Unblock checkbox on the General tab of the Properties dialog for the file". Handy when you have been sent a folder of them.

If the file is an email attachment, there is an ordering trick worth knowing. Microsoft's guidance is to save it to your hard drive first and then unblock it, or to save it to OneDrive before opening. Opening an attachment directly from the email is what drops it into a temporary folder and produces the "potentially unsafe location" message as well.

If there is no Unblock checkbox at all, do not go looking for a bigger hammer. That usually means the file is on a network share, and the answer belongs to the share rather than to your copy of Office.

Before you unblock anything: Microsoft’s three questions are better than ours

Microsoft puts a short checklist in front of end users on this exact error, and it is sharper than most security advice because it is about the situation rather than the technology. Paraphrased closely, the three questions are: were you expecting to receive a file with macros; is a stranger encouraging you to enable content; and is a pop-up message encouraging you to enable content.

The accompanying line deserves to be read twice, because it cuts against the reflex that makes attachments dangerous in the first place: "Never open a file attachment you weren't expecting, even if it appears to come from somebody you trust." A convincing sender name is the cheapest thing in the world to fake, which is a subject in its own right and one we have written about separately.

Microsoft also supplies the sentence that no page trying to sell you a macro-unblocking tool will ever print: "If a downloaded file from the internet or a file opened from a network share wants you to allow macros, and you're not certain what those macros do, you should probably just delete that file." That is Microsoft's advice, not ours, and for an unexpected attachment we think it is correct.

And the one that settles most arguments in an office: "No legitimate company will make you open an Excel file to cancel an order and you don't need macros just to read a document in Word." Microsoft's broader point is that "Macros aren't required for everyday use like reading or editing a document in Word or using Excel workbooks" — so a document that insists it needs macros merely to be read is making a claim about itself that is worth taking seriously.

Our own version of the check is one phone call. If the file is supposedly from your supplier, your bookkeeper or your bank, ring them on the number you already had — from a past invoice, from the back of a card, from your own contacts — and ask whether they sent a macro-enabled file. Never the number in the email. Microsoft's guidance on suspicious files says much the same: "To ease suspicion, you can call or email the person who sent you the file to confirm." This is the same out-of-band habit that stops a diverted-paycheck scam, and it costs two minutes.

Why it works on your colleague’s computer and not on yours

This comparison causes more confusion than the error itself, and there are several documented reasons for it that have nothing to do with the file being safe.

Someone who opened that file before the default changed may still be able to run it. Microsoft's flow is explicit: if the user previously opened the file "and selected Enable content from the Trust Bar, then the macros are enabled because the file is considered trusted". The file is on a list on their machine, and not on yours.

Where the file came from on their computer also changes the outcome, and these are the ones that catch offices on Microsoft 365. Microsoft documents that if a user selects Open in Desktop App from the OneDrive website or a SharePoint site, including a site used by a Teams channel, "then the file won't have Mark of the Web"; that if the OneDrive sync client downloads a file, "then the file won't have Mark of the Web"; and that files in Windows known folders — Desktop, Documents, Pictures, Screenshots and Camera Roll — synced to OneDrive "don't have Mark of the Web". Same file, same company, different route in, different answer.

Platform matters too. The change "only affects Office on devices running Windows" and only the applications Microsoft names: Access, Excel, PowerPoint, Project, Publisher, Visio and Word. And it "doesn't affect Office on a Mac, Office on Android or iOS devices, or Office on the web". So when the designer on the Mac says the file is fine, that is a statement about her platform, not about the file.

The three settings we ask small offices to leave alone

Almost every guide to this error eventually recommends one of three broad fixes. Each of them works, and each is wider than people realise, in ways Microsoft documents and the guides tend not to mention.

Trusted sites. Adding a file server or a website here stops the macro check for everything from that location — and Microsoft's warning goes further than Office: "If you add something as a trusted site, you're also giving the entire site elevated permissions for scenarios not related to Office." On the same page: "You'll trust all the macros from this site if you choose to apply this setting, so only do this if you know that every file opened from this location is trustworthy."

Trusted publishers. This is the best option for a genuine recurring supplier, but it is not a per-file decision. "All macros validly signed with the same certificate are recognized as coming from a trusted publisher and are run", and "adding a trusted publisher could affect scenarios beyond those related to Office, because a trusted publisher is a Windows-wide setting, not just an Office-specific setting."

Trusted Locations. Anything saved into one skips the Mark of the Web check entirely, which is why Microsoft says to "manage Trusted Locations carefully and use them sparingly", and says network locations can be set as Trusted Locations but that it is not recommended. The failure mode here is specific: trusting the Downloads folder, which is the one folder on the machine that unknown files arrive in by default, converts the protection into a formality. If you are going to use a Trusted Location, it should be a new, narrow folder that only one process writes to.

There is also a fourth thing worth knowing before you spend an evening on it. Much of the advice online is written for administrators and tells you to set a Group Policy. Microsoft's constraint: "You can only use policies if you're using Microsoft 365 Apps for enterprise. Policies aren't available for Microsoft 365 Apps for business." Microsoft 365 Business Standard is what a large share of small offices actually buy, so that route often does not exist for the person reading it.

When it is a real workflow rather than a one-off

None of the above means macros are illegitimate. Plenty of small businesses depend on them: the order form a distributor has emailed out every Monday for a decade, the quoting sheet from an equipment supplier, a line-of-business system that mails reports with macros in them. Microsoft explicitly contemplates that case when it describes a "line of business application" sending recurring reports with macros.

For those, in the order we would try them: ask the vendor whether they can digitally sign their macros, which is what Microsoft recommends to organisations and what lets you make one deliberate trust decision instead of a weekly one; or receive the file by a route that does not attach Mark of the Web in the first place, such as a synced OneDrive folder or Open in Desktop App; or, last, a single narrow Trusted Location that only that one process writes into. Unblocking each file by hand is fine for something that happens monthly and miserable for something that happens daily.

Worth asking out loud at least once, too: does that spreadsheet still need macros at all? A macro written years ago to do something the application has since learned to do by itself is a macro you can retire, and a form that no longer needs code is a form that stops raising this question forever. Sometimes the answer is no, the macros are load-bearing. It is a cheap question either way.

What we actually do about this on a service call

In practice this comes to us in two shapes. The urgent one is a small business that cannot open something it needs today — a supplier's order form, a payroll template, an insurance document, an old .xls from a bookkeeper who retired. The slower one is an office where somebody solved it months ago by turning the warnings off, and nobody has thought about it since.

For the first, the work is identifying which of the four mechanisms is actually in play, verifying the file is what it claims to be before anything is unblocked, then clearing that one file and leaving the machine's defaults intact. For the second, the work is putting the protections back without breaking the one legitimate workflow that caused someone to disable them — which is the part people are afraid of, and the reason the setting usually stays off.

We also keep an eye on the version of this that is not a technical problem at all: a file that was never from your supplier, sent to someone whose job is to open attachments from strangers. If a file arrives unexpectedly and wants macros, we would far rather spend ten minutes confirming it with a phone call than an afternoon recovering from it.

We look after computers, home and small-business networks, printers and email across Southern California and the Coachella Valley, onsite or remotely. If a file your business needs will not open, or you suspect somebody has switched off a protection to get through a deadline, that is usually a short conversation and a quick look rather than a project.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →