Appendix L: Outlook Add-In
The Outlook Add-In enhances user security awareness and actionability by integrating protection features directly into the Outlook application. The add-in supports the following primary use cases:
-
Misdirected Email Prevention
Identifies and alerts users to potential mistakes when sending emails, such as typos in recipient addresses, lookalike domains, or unauthorized external recipients. See Configuring Misdirected Email Prevention.
Misdirected Email Prevention requires a DLP license (either the DLP add-on or the Complete Package).
-
Report Phishing
Enables users to report suspicious emails directly from Outlook, contributing to faster threat detection and response. See Check Point Report Phishing Button.
-
Email Security Portal Access
Allows authorized users to quickly access the Email Security Administrator Portal to manage quarantined emails and submit restore requests directly from their inbox. See Accessing the Email Security Portal from Outlook.
Outlook Add-In Permissions
Microsoft may display the following permission requests when users sign in to the Email Security Outlook Add-In:
-
Maintain access to data you have given it access to
-
View users' basic profile
The Email Security Outlook Add-In requires only delegated Microsoft identity / OpenID Connect permissions for user authentication and session continuity.
Required Permissions
The Outlook Add-In requires the following scopes.
| Scope | Microsoft Permission Display | Purpose |
|---|---|---|
| offline_access | Maintain access to data you have given it access to |
Used only to maintain the authenticated user session and enable sign-in continuity. This scope does not grant additional access to mailbox data or contacts. |
| profile | View users' basic profile |
Used only to retrieve basic identity information required for user authentication and the sign-in process. |
Permissions Not Required
The Outlook Add-In does not require any Microsoft Graph application permissions and does not request or require permissions such as:
-
Mail.Read
-
Contacts.Read
-
User.Read.All