For years, Oracle EBS’s native Web ADI tool has quietly relied on one thing to move data between Excel and EBS: ActiveX controls. It’s legacy technology, and Microsoft has now made its position on that technology official. As part of its ongoing security hardening of Microsoft 365 and Office 2024, Microsoft is disabling ActiveX by default and recommending that organizations keep it disabled.
For any business still running Web ADI, that’s not a minor technical footnote — it’s a direct threat to a core piece of financial infrastructure.
The dependency nobody planned for
Web ADI was built in a different era of Office security, when ActiveX controls were a standard way to bridge Excel and enterprise applications. That plumbing is exactly what breaks when ActiveX is turned off. Oracle has acknowledged the issue but currently has no fix in place and is waiting on Microsoft, with no timeline provided for a resolution. In other words, this isn’t a “patch coming soon” situation — it’s an open-ended dependency on a vendor decision outside Oracle’s control.
What this actually means for Web ADI users
Complete Web ADI breakdown. Once IT departments align with Microsoft’s security recommendations and disable ActiveX, Web ADI’s Excel-to-EBS data loading stops working entirely. This isn’t a degraded experience — it’s a full outage of the tool.
Silent, unpredictable failures. This is the part that should worry finance and IT teams most. Ongoing Windows and Microsoft 365 security patches can intermittently disable ActiveX controls by default, with no advance warning. That means Web ADI can break in the middle of a period close, a reconciliation cycle, or a routine data load — not because anyone changed a setting on purpose, but because a routine patch rolled out overnight.
High-risk workarounds. Faced with a broken tool, organizations are effectively pushed into a bad trade-off: either fall back to manual data entry directly in EBS — think keying journals in by hand, which slows down period close and introduces error risk — or degrade enterprise security by lowering Excel’s ActiveX settings just to keep a legacy tool alive. Neither option is one a finance or security leader should have to choose.
Microsoft has been clear about why it’s making this change: ActiveX represents a well-documented and long-standing attack surface, and disabling it by default is a security best practice, not a preference.
A tool built on modern architecture doesn’t have this problem
This is precisely the scenario More4apps was built to avoid. Our Excel-based data loading solution for Oracle EBS and Oracle Fusion Cloud ERP operates 100% free of ActiveX dependencies. There’s no legacy plumbing to break, no race against the next security patch, and no forced choice between security and functionality. IT security teams can follow Microsoft’s best practices and block ActiveX entirely, without disrupting the finance team’s ability to load data into EBS.
But removing the ActiveX risk is really just the starting point. Once you’re not constrained by Web ADI’s architecture, you get functional advantages that legacy tools simply can’t offer:
Full template control. Web ADI’s standard templates are fixed and often missing what businesses actually need — descriptive flexfields, attachments, and other custom fields. More4apps lets you delete, reorder, or add columns freely, so the template matches your process instead of the other way around.
Pre-validation and instant feedback. Data errors get caught and corrected inside Excel, with clear, user-friendly feedback, before anything is uploaded to EBS. That means fewer failed loads, fewer support tickets, and less time spent troubleshooting after the fact.
Upgrade resilience. Because it’s built on modern architecture rather than deprecated Microsoft technology, More4apps stays resilient against the ongoing Microsoft security patches and Oracle system upgrades that keep breaking Web ADI. You’re not rebuilding your data-loading process every time Microsoft or Oracle ships an update.
The clock is already running
This isn’t a hypothetical future risk — Microsoft’s rollout is happening now, and every security patch cycle increases the odds that Web ADI quietly stops working for someone in your organization. Waiting for Oracle to deliver a fix means waiting on a timeline that doesn’t exist yet.
For finance and IT teams that depend on Excel-based data loading into Oracle EBS or Fusion Cloud, the ActiveX shutdown is a good moment to ask a simple question: is your data loading process built on technology Microsoft is actively phasing out, or on something designed to keep working regardless of what Microsoft or Oracle changes next?
If you want to see how More4apps handles the transition away from Web ADI, we’re happy to walk through it.
