Can Outlook Add-ins be deployed through Intune or Configuration Policies and assigned to device groups?

Pranjal Kumar Pandey 0 Reputation points
2026-09-28T09:45:49.6933333+00:00

I am working on a use case called "Set Outlook Plugin" and would like to understand the recommended Microsoft approach for deploying and managing Outlook add-ins.

My objective is to automatically assign a specific Outlook add-in/plugin to a targeted set of users or devices without requiring manual installation by end users.

I would appreciate clarification on the following:

1.Is there any Intune Configuration Policy, Administrative Template, Settings Catalog policy, or other device management policy that can be used to deploy or enforce Outlook add-ins?

2.Can Outlook add-ins be assigned to Microsoft Entra ID groups, device groups, or user groups?

3.If the add-in is already available in the Microsoft Marketplace or as a custom manifest, what are the recommended deployment steps for enterprise environments?

4.Are there any limitations when deploying add-ins to New Outlook, Classic Outlook, and Outlook on the Web?

Our goal is to determine whether the "Set Outlook Plugin" use case should be implemented through Intune policies, PowerShell automation, or Microsoft 365 Centralized Deployment.

Any guidance, best practices, or official Microsoft documentation would be greatly appreciated.

Thank you.

Microsoft Security | Intune | Application management

2 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. AI answer

    2026-09-28T09:46:14.2+00:00

    Yes. The recommended Microsoft approach for Outlook add-ins is Microsoft 365 centralized deployment, not Intune device configuration policies.

    1. Intune policy support
      • The provided Intune documentation for Outlook for iOS and Android covers app configuration settings and feature controls such as Save Contacts, Sync Calendars, and Add-ins availability.
      • It does not describe deploying Outlook add-in packages/manifests through Intune configuration policies.
      • For Outlook mobile, Intune can control whether add-ins are available by using:
        • Intune App Protection Policy: Sync policy managed app data with native apps or add-ins
        • Managed apps App Configuration Policy: Allow Add-ins
      • If Sync policy managed app data with native apps or add-ins is set to Block, add-ins are disabled and related app configuration settings are ignored.
    2. Assignment targets
      • Outlook add-ins can be assigned through centralized deployment to:
        • Everyone
        • Specific users
        • Groups
        • Just me for testing
      • Group-based assignment is recommended because membership changes automatically add or remove access.
      • The supported assignment model in the provided documentation is users and groups within the organization. The context does not support deployment to device groups for Outlook add-ins.
    3. Recommended enterprise deployment steps
      • Use the integrated apps portal as the recommended and most feature-rich method for most customers.
      • If using the add-in admin center flow:
        1. Open the Microsoft 365 admin center add-in deployment experience.
        2. Provide the add-in manifest, including a manifest URL if applicable.
        3. Choose who gets the add-in: Everyone, Specific users/groups, or Just me.
        4. Select Deploy.
        5. Test after deployment.
      • Centralized deployment supports automatic download when the relevant Office app starts.
      • For line-of-business add-ins, admins can upload a new manifest file to update metadata.
    4. Platform and client limitations
      • Centralized deployment supports:
        • Office on Windows and Mac
        • Office for the web
        • Outlook Mobile Add-ins only on iOS and Android
      • The context does not explicitly distinguish “New Outlook” versus “Classic Outlook” behavior. It does confirm Outlook add-ins can be centrally deployed to supported Outlook clients and that users might need to relaunch the app.
      • After centralized deployment, the add-in can take:
        • up to 24 hours to appear on all users’ clients
        • 24–72 hours to appear on the ribbon in some cases
    5. Important operational guidance
      • For Outlook on iOS and Android, avoid configuring add-in policies in both Microsoft Intune and the Microsoft 365 Admin Center at the same time. Microsoft recommends choosing one method for add-in policy control.
      • For granular add-in control, the Microsoft 365 Admin Center provides more specific configurations than Intune.
      • If assigning broadly, use Everyone sparingly and prefer group-based assignment.

    For the “Set Outlook Plugin” use case, the supported Microsoft approach in the provided documentation is:

    • Use Microsoft 365 Centralized Deployment / Integrated Apps to deploy the add-in itself.
    • Use user or group assignment, preferably Microsoft Entra ID-backed groups where group membership controls access.
    • Use Intune only for mobile Outlook add-in availability controls, not as the primary deployment mechanism for the add-in package.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.