The new Microsoft Outlook prevents DLP from monitoring emails on Windows endpoints

Data Loss Prevention

2 more products

22210

07 September 2023

26 May 2023

The new Microsoft Outlook does not support COM plug-ins on Windows. As a result, when users enable the Try the new Outlook UI toggle in Outlook, DLP Agent cannot monitor outgoing emails on Windows endpoints.

Broadcom has verified these findings with Outlook version 2304 and the new Outlook version 1.2023.516.100 on Windows.

Currently, the new Outlook on Windows is available for Microsoft Exchange-based Microsoft 365 accounts only. The new Outlook is not available for on-premises deployments or hybrid deployments of Exchange Server. For more information, visit Getting started with the new Outlook for Windows at the Microsoft Support website.

Broadcom is working on a replacement solution to monitor the new Outlook using add-ins.

To prevent users from enabling the new Outlook, enterprise administrators can use one of the following methods:

  • Disable the Try the new Outlook UI toggle using a GPO policy (Recommended).
  • Disable the new Outlook for Windows endpoints in Microsoft Exchange Online.

Disabling the toggle using a GPO policy

Perform the following steps:

  1. On the Microsoft Active Directory Server, open the Group Policy Management console.
  2. Create or edit a linked GPO policy in the desired domain.
  3. In the Group Policy Management Editor, navigate to User Configuration > Preferences >Windows Settings.
  4. Under Windows Settings, right-click Registry and select New > Registry Item.
  5. In the General tab of the New Registry Properties window, configure the following settings:
    • Hive: HKEY_CURRENT_USER
    • Key Path: Software\Microsoft\Office\16.0\Outlook\Options\General
    • Value Name: HideNewOutlookToggle
    • Value Type: REG_DWORD
    • Value Data: 1
    • Base: Hexadecimal
  6. Click OK.
  7. Enforce the new or modified GPO policy.

Disable the new Outlook mode for Windows endpoints in Microsoft Exchange Online

Follow the instructions that are provided at the Microsoft Learn website. For more information, visit Enable or disable access to the new Outlook for Windows.

A limitation of this method is that the Try the new Outlook UI toggle remains visible. If users attempt to enable the new Outlook, they receive an error message and Outlook fails to launch. After a minute, Outlook reverts to the original user interface upon launch.