Managing apps and software deployment through Microsoft Intune
Yes. The recommended Microsoft approach for Outlook add-ins is Microsoft 365 centralized deployment, not Intune device configuration policies.
- Intune policy support
- The provided Intune documentation for Outlook for iOS and Android covers app configuration settings and feature controls such as Save Contacts, Sync Calendars, and Add-ins availability.
- It does not describe deploying Outlook add-in packages/manifests through Intune configuration policies.
- For Outlook mobile, Intune can control whether add-ins are available by using:
- Intune App Protection Policy: Sync policy managed app data with native apps or add-ins
- Managed apps App Configuration Policy: Allow Add-ins
- If Sync policy managed app data with native apps or add-ins is set to Block, add-ins are disabled and related app configuration settings are ignored.
- Assignment targets
- Outlook add-ins can be assigned through centralized deployment to:
- Everyone
- Specific users
- Groups
- Just me for testing
- Group-based assignment is recommended because membership changes automatically add or remove access.
- The supported assignment model in the provided documentation is users and groups within the organization. The context does not support deployment to device groups for Outlook add-ins.
- Outlook add-ins can be assigned through centralized deployment to:
- Recommended enterprise deployment steps
- Use the integrated apps portal as the recommended and most feature-rich method for most customers.
- If using the add-in admin center flow:
- Open the Microsoft 365 admin center add-in deployment experience.
- Provide the add-in manifest, including a manifest URL if applicable.
- Choose who gets the add-in: Everyone, Specific users/groups, or Just me.
- Select Deploy.
- Test after deployment.
- Centralized deployment supports automatic download when the relevant Office app starts.
- For line-of-business add-ins, admins can upload a new manifest file to update metadata.
- Platform and client limitations
- Centralized deployment supports:
- Office on Windows and Mac
- Office for the web
- Outlook Mobile Add-ins only on iOS and Android
- The context does not explicitly distinguish “New Outlook” versus “Classic Outlook” behavior. It does confirm Outlook add-ins can be centrally deployed to supported Outlook clients and that users might need to relaunch the app.
- After centralized deployment, the add-in can take:
- up to 24 hours to appear on all users’ clients
- 24–72 hours to appear on the ribbon in some cases
- Centralized deployment supports:
- Important operational guidance
- For Outlook on iOS and Android, avoid configuring add-in policies in both Microsoft Intune and the Microsoft 365 Admin Center at the same time. Microsoft recommends choosing one method for add-in policy control.
- For granular add-in control, the Microsoft 365 Admin Center provides more specific configurations than Intune.
- If assigning broadly, use Everyone sparingly and prefer group-based assignment.
For the “Set Outlook Plugin” use case, the supported Microsoft approach in the provided documentation is:
- Use Microsoft 365 Centralized Deployment / Integrated Apps to deploy the add-in itself.
- Use user or group assignment, preferably Microsoft Entra ID-backed groups where group membership controls access.
- Use Intune only for mobile Outlook add-in availability controls, not as the primary deployment mechanism for the add-in package.