Microsoft 365 Add-In Security: What CIS Says SMBs Should Do Now
- Hanna Korotka
- Jun 11
- 2 min read

By default, anyone in your organization can install add-ins directly into Outlook, Word, Excel, and PowerPoint — no approval needed. Add-ins can read emails, access contacts, and pull data from documents. Most are fine. But a malicious or compromised one can silently exfiltrate data every single day, and you'd never know.
The Center for Internet Security (CIS) calls this out in their Microsoft 365 benchmark. The fix takes under 15 minutes.
What CIS Actually Says About Microsoft 365 Add-In Security
The CIS Microsoft 365 Benchmark includes two specific controls that address Microsoft 365 add-in security for businesses running E3 or E5 licenses. Here's what they mean in plain English.
Control 6.3.1 — Lock Down Outlook Add-Ins
Three Exchange Online roles let users self-install Outlook add-ins with full mailbox access: My Custom Apps, My Marketplace Apps, and My ReadWriteMailbox Apps. CIS says remove them from the default role assignment policy.
Fix it in 3 steps:
Exchange Admin Center → Roles → User Roles → Default Role Assignment Policy → Manage Permissions
Uncheck all three roles
Save
Control 1.3.4 — Restrict Add-Ins in Word, Excel, and PowerPoint
This is a Level 1 control — recommended for every organization. Users shouldn't be able to browse the Office Store or install add-ins without admin review.
Fix it in 3 steps:
Microsoft 365 Admin Center → Settings → Org Settings → User owned apps and services
Uncheck Let users access the Office Store and Let users start trials
Save
"But My Team Needs Their Add-Ins"
No problem. Use Centralized Deployment — built into the Microsoft 365 Admin Center — to push approved add-ins to specific users or groups. They appear automatically, no user action required. Take inventory of what your team uses today, deploy the legitimate ones centrally, then remove user permissions. Microsoft's step-by-step guide
Need Help Tightening Your Microsoft 365 Security?
Implementing CIS controls is a great start — but it's just one piece of the picture. We help SMBs improve their Microsoft 365 Security and Compliance posture so your environment is protected, auditable, and ready for what's next. Get in touch to see where you stand.





Comments