The new Microsoft Outlook prevents DLP from monitoring emails on Windows endpoints
22210
07 September 2023
26 May 2023
The new Microsoft Outlook does not support COM plug-ins on Windows. As a result, when users enable the Try the new Outlook UI toggle in Outlook, DLP Agent cannot monitor outgoing emails on Windows endpoints.
Broadcom has verified these findings with Outlook version 2304 and the new Outlook version 1.2023.516.100 on Windows.
Currently, the new Outlook on Windows is available for Microsoft Exchange-based Microsoft 365 accounts only. The new Outlook is not available for on-premises deployments or hybrid deployments of Exchange Server. For more information, visit Getting started with the new Outlook for Windows at the Microsoft Support website.
Broadcom is working on a replacement solution to monitor the new Outlook using add-ins.
To prevent users from enabling the new Outlook, enterprise administrators can use one of the following methods:
- Disable the Try the new Outlook UI toggle using a GPO policy (Recommended).
- Disable the new Outlook for Windows endpoints in Microsoft Exchange Online.
Disabling the toggle using a GPO policy
Perform the following steps:
- On the Microsoft Active Directory Server, open the Group Policy Management console.
- Create or edit a linked GPO policy in the desired domain.
- In the Group Policy Management Editor, navigate to User Configuration > Preferences >Windows Settings.
- Under Windows Settings, right-click Registry and select New > Registry Item.
- In the General tab of the New Registry Properties window, configure the following settings:
- Hive: HKEY_CURRENT_USER
- Key Path: Software\Microsoft\Office\16.0\Outlook\Options\General
- Value Name: HideNewOutlookToggle
- Value Type: REG_DWORD
- Value Data: 1
- Base: Hexadecimal
- Click OK.
- Enforce the new or modified GPO policy.
Disable the new Outlook mode for Windows endpoints in Microsoft Exchange Online
Follow the instructions that are provided at the Microsoft Learn website. For more information, visit Enable or disable access to the new Outlook for Windows.
A limitation of this method is that the Try the new Outlook UI toggle remains visible. If users attempt to enable the new Outlook, they receive an error message and Outlook fails to launch. After a minute, Outlook reverts to the original user interface upon launch.