How Password Protection Actually Works in Excel

Excel has had built-in password protection for decades, and it is still widely misunderstood. Most people think adding a password means their workbook is secure. It is not, not in any meaningful sense. The protection is real but weak by modern standards, which makes it fine for casual use and useless against anyone who actually wants in. To password protect a workbook, go to the Review tab, click Protect Workbook, and enter a password when prompted. This locks the structure so sheet order cannot be changed, new sheets cannot be added, and hidden sheets cannot be unhidden. To protect an individual sheet, you select Protect Sheet from the same Review tab, choose what actions users are allowed to perform, and set a password. These two levels do different things. Protect Workbook keeps the layout locked. Protect Sheet controls cell-level editing. If you want to protect a file so it cannot be opened without a password, that is a completely different setting. Go to File, then Info, then Protect Workbook, and choose Encrypt with Password. This uses AES encryption to scramble the entire file. The password is required just to open the document.

I have spent years handing this explanation to people who came to me convinced they had secured a spreadsheet. They had not. They had only protected the sheet structure while leaving every cell readable and editable by anyone who could get past the first layer. The distinction between Protect Workbook, Protect Sheet, and Encrypt with Password matters more than most spreadsheet users realize.

The Real Limitations Nobody Talks About

Password protection in Excel is not security. It is a convenience feature with a gate. The passwords are stored as hashes, but the hashing algorithm in older versions of Excel is trivially reversible. Excel 2010 and earlier used RC4 encryption with a 40-bit key. That is not hyperbole. A tool called John the Ripper can crack a standard Excel password in under ten minutes on a basic laptop. Excel 2013 and later upgraded to AES-128 or AES-256, which is significantly harder to break, but not impossible given enough time and compute resources. The biggest problem I keep running into is lost passwords. I had a client who needed access to a financial model from 2018 that had been encrypted with a password they no longer remembered. They did not back it up because they assumed the password was safe. The file was small, roughly 4 MB, but the model contained years of rolling forecasts. We tried a few recovery tools. One of them worked within two days of processing on a mid-range GPU. The password turned out to be a single word with a number appended. Simple, common, and permanently locked behind a layer of encryption that offered no recovery path except brute force. This is the reality of Excel password protection: if you lose the password, the data is effectively gone unless you are willing to spend money on recovery software or wait for hardware to chew through the encryption. There is no backdoor from Microsoft. There never has been.

Get the Full Details

Password Protect Worksheet Excel Protect Ranges With Different
Password Protect Worksheet Excel Protect Ranges With Different

Common Pitfalls When Setting Up Protection

The first mistake people make is protecting the wrong thing. They spend ten minutes locking down a sheet only to share the workbook without a password, leaving the data exposed to anyone with the file. The second mistake is trusting the password alone as the sole protection layer. If you store the file on a network drive or in cloud storage without additional access controls, the password is the only thing standing between sensitive data and anyone with read access. A third pitfall involves macro-enabled files. Passwords set on standard workbooks do not always carry over to VBA project protection. The VBA editor has its own separate password system, and it is entirely independent. I once spent three hours trying to recover a workbook because the user had protected the file at the sheet level but left the VBA code completely unprotected. Anyone could view the macros, copy the logic, and modify the spreadsheet without hitting a single password prompt. There is also the issue of shared workbooks. When you enable the legacy Shared Workbook feature, password protection becomes unreliable. Excel will sometimes ignore sheet protection settings or reset them unexpectedly. Microsoft has warned about this for years. The feature is deprecated but still ships in Excel 365. Use it only if you have no alternative, and do not rely on it for anything that requires data integrity.

What You Should Actually Do Instead

If you need real security, password protect the file with the Encrypt option, use a strong password that is at least twelve characters long with mixed case and numbers, and store it in a password manager. Do not reuse that password anywhere else. Then put the file inside a properly secured folder with access controls managed through your IT department or cloud platform. Add two-factor authentication to your cloud storage if it is available. Consider whether the data even needs to live in Excel at all. A database with proper access controls will serve you better than any spreadsheet protection scheme. For most day-to-day office work, the basic Protect Sheet and Protect Workbook features are adequate. They stop accidental edits and keep junior staff from rearranging your layout. But do not confuse that with security. It is not. It is a minor inconvenience layer, and it should be treated as such.