I have a need to embed an iFrame into a page for a marketing campaign. This requires me to turn on Confluence HTML macros at the add-on level. While I have removed admin rights from all of the spaces, users would still have the ability to add the HTML macro to their page. I don't think that our users would do anything malicious but I don't want to risk opening us up to cross-site vulnerabilities mentioned every. That being said, is there any way to restrict the use of the HTML macro by space? As we'll be moving to Service Desk in the very near future, I was hoping to have the ability to do this for our knowledge base as well. Thanks.