The quickest way: password protection built into Excel

Excel has a built-in password feature that encrypts your file so it cannot be opened without the correct password. You do not need extra software. Open the file you want to protect, go to File > Info > Protect Workbook, then select Encrypt with Password. Type your password twice and save the file. Anyone who tries to open it will be prompted for the password first.

This method works on Windows and Mac versions of Excel, and on the web version at Office.com. The password you set is the only way in — if you forget it, Microsoft cannot recover the file for you. Write it down somewhere safe, or use a password manager to store it.

The encryption Excel uses is AES-256, which is the same standard used by banks and government agencies. For most everyday files — spreadsheets with personal finances, client lists, or sensitive work data — this is sufficient protection.

Key Takeaways

  • Excel's built-in password protection encrypts your file using AES-256 encryption, the same standard used for banking and government data.
  • To set a password, open the file, go to File > Info > Protect Workbook > Encrypt with Password, type your password twice, and save.
  • If you forget your password, the file cannot be recovered — Microsoft does not have a backdoor to unlock it.
  • On a shared computer, password protection prevents other users from opening the file, but does not prevent them from deleting it.
  • For files stored in OneDrive or SharePoint, you can also restrict who can view or edit the file through sharing permissions, which works alongside password protection.

What password protection actually does and does not do

Password protection stops someone from opening your file and reading its contents. It does not hide the file itself — anyone with access to your computer or cloud storage can see that the file exists and try to open it. It also does not prevent someone from deleting the file, moving it, or copying it to another location.

If your file is stored on a shared computer or network drive, password protection only protects the contents. A coworker cannot read your spreadsheet without the password, but they can still see the filename and potentially delete it. If you need to prevent people from even seeing that a file exists, you need file-level permissions on your operating system or cloud storage, not just a password inside the file.

Setting a strong password you can actually remember

A strong password for your Excel file should be at least 12 characters long and mix uppercase letters, lowercase letters, numbers, and symbols. Examples: BlueMoon$2024! or Coffee7@Desk#Work. Avoid passwords based on your name, birthdate, or common words that appear in a dictionary.

If you use the same password for multiple files, write each password down separately or use a password manager like Bitwarden, 1Password, or KeePass. These tools store passwords encrypted on your device or in a secure vault, so you only have to remember one master password. If you write passwords on paper, keep the paper in a locked drawer, not on a sticky note on your monitor.

Test your password before you rely on it. Close the file, reopen it, and confirm the password works. This catches typos before you forget what you meant to type.

Encrypting files stored in OneDrive or SharePoint

If your Excel file lives in OneDrive or SharePoint, you have two layers of protection: the password inside the file, and the sharing permissions on the folder or file itself. Password protection encrypts the file so only someone with the password can read it. Sharing permissions control who can even see the file in the first place.

To restrict access through OneDrive or SharePoint, right-click the file, select Share, and choose who can view or edit it. You can also set an expiration date so the link stops working after a certain date. This prevents the file from being shared with the wrong person by accident, but it does not encrypt the file itself — Microsoft employees with access to your account could theoretically read it.

For maximum protection of sensitive files in cloud storage, use both: set a password inside the Excel file, and restrict sharing permissions to only the people who need access. This way, even if someone gains access to your OneDrive account, they still cannot read the file without the password.

Removing or changing a password later

To remove the password from an encrypted Excel file, open the file (you will be prompted for the password), go to File > Info > Protect Workbook > Encrypt with Password, and leave the password field blank. Click OK and save the file. The file is no longer encrypted.

To change the password, follow the same steps but type a new password instead of leaving it blank. You must know the current password to change it — there is no "forgot password" option.

When password protection is not enough

Password protection inside an Excel file protects against casual access — someone borrowing your laptop, a coworker opening a file they should not see, or a file being shared by mistake. It does not protect against determined attackers with specialized tools, though cracking a strong AES-256 password would take years of computing power.

If your file contains highly sensitive data — trade secrets, medical records, financial account numbers, or information covered by regulations like HIPAA or GDPR — consider whether Excel is the right tool at all. Some organizations use dedicated data management software with additional security features like audit logs (records of who accessed the file and when), automatic backups, and encryption at rest and in transit.

For most everyday use — protecting a personal budget, client contact list, or work project from casual access — Excel's password protection is appropriate and sufficient.

Frequently Asked Questions

Can someone crack my Excel password?

A strong password (12+ characters, mixed case, numbers, symbols) would take years to crack with current technology. Weak passwords (like "password123" or your name) can be cracked in hours or days. Use a password manager to generate and store a strong password, and you will be protected against all but the most determined attackers.

What happens if I forget my Excel password?

Microsoft cannot recover it. The file is encrypted, and the password is the only key. If you forget it, the file is inaccessible. This is why storing passwords in a password manager or writing them down in a secure location is important.

Does password-protecting an Excel file slow it down?

No. Encryption and decryption happen when you open and save the file, not while you are working in it. You will not notice any performance difference.

Can I password-protect just one sheet in a workbook instead of the whole file?

Excel allows you to lock individual sheets (so someone cannot edit or delete them) but not to password-protect a single sheet while leaving others open. To protect one sheet, move it to a separate file and password-protect that file.

Is password protection enough if my file is on a USB drive?

Password protection encrypts the file itself, so it is protected even if the USB drive is lost or stolen. However, the USB drive itself is not encrypted — someone could delete the file or copy it. For maximum protection of a USB drive, encrypt the entire drive using BitLocker (Windows) or FileVault (Mac), then also password-protect individual sensitive files inside it.