Skip to main content

Ensure users installing Outlook add-ins is not allowed

Remediation Considerations

MaxScoreImplementationCostUserImpact
3UnknownUnknown

Remediation Impact

Implementing this change will impact both end users and administrators. End users will be unable to integrate third-party applications they desire, and administrators may receive requests to grant permission for necessary third-party apps

Remediation

To prohibit users installing Outlook add-ins:

  1. Navigate to Exchange admin center https://admin.exchange.microsoft.com.

  2. Click to expand Roles select User roles.

  3. Select Default Role Assignment Policy.

  4. In the properties pane on the right click on Manage permissions.

  5. Under Other roles uncheck My Custom Apps, My Marketplace Apps and My ReadWriteMailboxApps.

  6. Click Save changes.

Note - This security control will take into account only the default policy. It is suggested to set the above for all the policies.