SafeToOpenEmail Security Docs

SafeToOpen Browser Security

Outlook: Microsoft 365 deployment

Integrated apps from AppSource or the branded manifest per workspace, group import from Entra ID, multi-tenant for MSPs, verification

Guide 2 of 7 · April 2026

Result: every mailbox you choose has SafeToOpen in Outlook on Windows, Mac, the web and mobile, licensed the first time it opens, with no email and no click. Time: about 20 minutes, then up to 24 hours for Microsoft to push the add-in.

What you will need#

1. Choose the add-in package#

Standard add-in from AppSourceBranded manifest from the console
Name and icon in Outlook“SafeToOpen Email Verification”, SafeToOpen iconYour organisation or workspace name, button label and logo (guide 4)
UpdatesAutomaticAutomatic (same code and URLs; only identity differs)
Per workspaceOne package for everyoneOne manifest per workspace, deployed to that workspace’s group
WhereIntegrated apps → Get appsIntegrated apps → Upload custom apps

2. Deploy from the Microsoft 365 admin center#

2a. Standard add-in#

  1. admin.microsoft.com → Settings → Integrated apps → Get apps. Search “SafeToOpen” and choose “SafeToOpen Email Verification” → Get it now.
  2. Assign users: Entire organisation, or Specific users/groups (use the same groups you will import in section 3).
  3. Deployment method: Fixed (always visible, user cannot remove) is the recommended setting. Accept permissions and Finish deployment.

2b. Branded manifest per workspace#

  1. Console → Workspaces → the workspace → Policies & branding → set the display name, add-in name, button label and logo → Download add-in manifest. Repeat per workspace; the organisation default manifest is available on the same page without a workspace.
  2. admin.microsoft.com → Settings → Integrated apps → Upload custom apps → Office Add-in → Upload manifest file (.xml) → choose the downloaded file.
  3. Assign the workspace’s group, deployment method Fixed, finish. Each manifest has its own stable identifier, so several workspaces can coexist in one tenant and a user in two groups sees two buttons.
Note A branded manifest replaces the AppSource listing for those users; do not deploy both to the same group. Re-download and re-upload the manifest after changing the add-in name, button label or logo; behaviour policies do not need a re-upload.

3. Import people from Entra ID#

  1. Console → Microsoft 365 → Connect a tenant. Sign in with an account that can grant admin consent (Global Administrator, or Application Administrator with the rights to consent). SafeToOpen reads group membership only.
  2. Map groups: for each Entra ID group choose the workspace and the seat type (Plus or Executive). A person in two mapped groups gets the higher seat.
  3. Invite emails: switch off when the add-in is deployed centrally (this guide); the import then assigns seats silently. Leave on if some people install the add-in themselves.
  4. Sync now. Afterwards SafeToOpen receives change notifications from Microsoft and re-syncs; leavers are removed and their seats freed, and can receive an access-removed email if you switch that on.

MSPs: connect several tenants. Each tenant has its own label, default workspace and switches; groups from different tenants can map to different workspaces of the same organisation.

4. Verify#

  1. On a test mailbox, open Outlook (new Outlook, Outlook on the web or desktop). The button appears in the ribbon or message surface within 24 hours; sign out and in again to hurry it.
  2. Open a message and click the button. The panel shows your branding and a score with no sign-in prompt.
  3. Console → People shows the member as active; Console → Activity log shows the join.
  4. Report the test message from the panel; it appears under Incidents within a minute.

5. Executive seats and Deeper Analysis#

Executive members get impersonation and writing-style checks. If the workspace policy enforces automatic Deeper Analysis (guide 4), the panel shows “Still analysing…” for a few seconds after the quick score and then the final verdict; auto-forwarding of dangerous messages and tagging happen only on that final verdict, and one incident is recorded rather than two.

6. Removing#