An Outlook add-in is software connected to a high-value communications system. Even legitimate add-ins may read or write business data depending on the permissions and design, so installation should not be an unmanaged end-user decision.
What the evidence supports
Microsoft documents a permissions model for Office add-ins and recommends centralized deployment through the Microsoft 365 admin center. Microsoft notes that administrators can assign add-ins to specific users or groups and that an add-in’s hosted web application can change over time.
Why it matters to a Connecticut operator
The defensible control is application governance: know what is installed, who approved it, what it can access, and how it will be removed. This article does not claim that all add-ins are dangerous.
Operator checklist
- Inventory deployed add-ins and record owner, purpose, users, permissions, and review date.
- Use centralized deployment and group-based assignment instead of unmanaged installation.
- Remove unused add-ins and reassess those with access to mail or documents.
- Include add-ins and connected applications in offboarding and incident-response procedures.
