SafeToOpen Browser Security
Platform coverage and user freedom
Outlook and Gmail on desktop, web and mobile, what other clients cannot do, and what a user can still change
The honest map. “Enforced” means the administrator decides and the user cannot change it.
| Client | Install | Licensing | Can the user remove it? | Why |
|---|---|---|---|---|
| Outlook on Windows and Mac (Microsoft 365) | Enforced (Integrated apps, Fixed) | Automatic on first open | No | Add-ins deployed from the admin center are pinned by Microsoft and sign in with the mailbox identity. |
| Outlook on the web | Enforced | Automatic | No | Same deployment. |
| Outlook mobile (iOS, Android) | Enforced | Automatic | No | Same deployment; the add-in appears in the message actions menu. Some features that need the full pane are reduced. |
| Classic Outlook with Exchange Server on-premises | Not supported | — | — | The add-in relies on Microsoft 365 single sign-on and Exchange Online APIs; there is no admin deployment path for on-premises Exchange. |
| Gmail on the web (Google Workspace) | Enforced (domain install) | Automatic on first open | No | Domain-installed Marketplace add-ons cannot be removed by users. |
| Gmail apps (Android, iOS) | Enforced | Automatic | No | Workspace add-ons run in the mobile apps. |
| Personal Gmail (@gmail.com) | User installs from the Marketplace | Automatic once the address is on People | Yes | No admin console; the person is a member like any other but can uninstall. |
| Apple Mail, Thunderbird, other IMAP clients | Not available | — | — | These clients have no add-in framework the product can run in. Cover those mailboxes with mail-flow rules or use Outlook or Gmail. |
| Shared mailboxes and delegates (Outlook) | Enforced | Counts as the delegate’s seat | No | The signed-in user is the delegate; the shared mailbox itself is not a member. |
What the user can and cannot change#
- Removal — Remove or hide the add-in: not when deployed by the admin. Where the user installed it themselves (personal Gmail, or a tenant that allows self-install) they can.
- Settings — Automatic Deeper Analysis, auto-forward, tagging, auto link scanning, security tips: each is either enforced by the workspace policy or left to the user. Enforced switches are visible but disabled, with a note that the organisation manages them.
- Actions — Reporting a message, disputing a verdict, asking for Deeper Analysis (Executive seats): always available.
- Visibility — Seeing incidents from other people: never; only analysts and administrators see the console.
Note Rule of thumb: Outlook on Microsoft 365 and Gmail on Google Workspace are fully unattended and locked, on every device. Everything else is either self-installed or not covered. Do not sell beyond that.