Skip to main content
← Back to blog

Manage Outlook Add-Ins Like Connected Applications

Why Microsoft 365 add-ins need an owner, a business purpose, permission review, and centralized deployment.

By Alex Castrillo3 min readFact-checked August 28, 2026
Manage Outlook Add-Ins Like Connected Applications

An Outlook add-in is software connected to a high-value communications system. Even legitimate add-ins may read or write business data depending on the permissions and design, so installation should not be an unmanaged end-user decision.

What the evidence supports

Microsoft documents a permissions model for Office add-ins and recommends centralized deployment through the Microsoft 365 admin center. Microsoft notes that administrators can assign add-ins to specific users or groups and that an add-in’s hosted web application can change over time.

Why it matters to a Connecticut operator

The defensible control is application governance: know what is installed, who approved it, what it can access, and how it will be removed. This article does not claim that all add-ins are dangerous.

Operator checklist

  • Inventory deployed add-ins and record owner, purpose, users, permissions, and review date.
  • Use centralized deployment and group-based assignment instead of unmanaged installation.
  • Remove unused add-ins and reassess those with access to mail or documents.
  • Include add-ins and connected applications in offboarding and incident-response procedures.
Scope note: This briefing separates documented facts from practical recommendations. It is cybersecurity guidance, not legal advice or a statement that every recommended control is expressly required by Connecticut cannabis regulations.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.