Outbound Guard (Outlook)
Send-time personal-data protection for Outlook compose and send.
Outbound Guard is an Outlook add-in for Outlook compose and send. Offline SoftBlock covers configured deterministic categories (CPR by default; email, phone, IBAN, and cards when enabled in policy). With the org Outlook package, cloud sanitize uses the org’s selected categories plus AI person/organization names when AI is enabled.
How it works
Outlook compose
To: journalist@press.dk
CPR
SoftBlock
Don't Send, or wipe then send
Policy picks Warn, Warn + reason, or Block.
Policy
Open Settings → Organization: start with a preset (Recommended, Onboarding mode, Law firm, Municipality, Finance, or Custom), then adjust essentials (what to protect, SoftBlock severity, trusted domains). Onboarding mode uses the Recommended detectors with send prompts off, so a pilot does not interrupt mail. Open Customize for allowlists, custom detectors, recipient risk rules, attachments, team profiles, and audit options. By default SoftBlock runs only when any To/Cc/Bcc recipient is outside your trusted domains.
When personal data remains
- Warn shows Don't Send and Send Anyway.
- Warn + reason shows Don't Send and Add reason: pick why in Guard, then Send Anyway.
- Block shows Don't Send only: wipe in Guard, then send. Block is still Microsoft SoftBlock, so Outlook can send if the add-in cannot load.
Quick POC
On Outbound Guard / Enterprise / Trial, open Outbound Guard → Setup → Try without admin. Download the Outlook manifest, then open https://aka.ms/olksideload → My add-ins → Custom Addins → Add a custom add-in → Add from File. Microsoft's new Apps store cannot install custom XML; use that dialog.
If Outlook returns “Sideloading rejected by Exchange”, the tenant likely blocks user-installed custom add-ins. Use Org-wide deploy (Integrated apps), or ask an admin to enable Apps for Outlook (AppsForOfficeEnabled) and the My Custom Apps role for your mailbox.
Org-wide deploy
Download the deployment ZIP from Outbound Guard → Setup and upload the Outlook manifest in Microsoft 365 admin center → Settings → Integrated apps (Centralized Deployment). Cloud scan for your org is already in that XML. Sideload XML from Try without admin stays CPR-only.
If a downloaded package leaks, rotate Outlook access on Outbound Guard → Setup, download the ZIP again, and re-upload the XML. Cloud sanitize (POST /api/v1/sanitize) runs the full deterministic pattern set plus AI person/organization names when AI is enabled.
Confidential intent: with cloud scan, Outbound Guard can review subject and body for leaks that are not just numbers (playbooks, how we undercut competitors, unpublished pricing, credentials). High-risk intent SoftBlocks on send even when no CPR is present.
IT Ops alerts: org admins open Outbound Guard to acknowledge or resolve flags from SoftBlock, send overrides, high finding volume, or intent. Insights shows category counts, high-risk mailboxes, and destination domains. Telemetry stores mailbox, counts, intent labels, and domains, not message bodies. Subscribe a webhook to outbound_guard.alert for SIEM.
Correspondents: maintain an org directory (citizen, client, opposing, press, authority). Own email on To/Cc is allowed. Any CPR SoftBlocks. Press and opposing escalate. Override sends once.
Attachments are inspected on Send (PDF and Office text extract, with a timeout). Unscanned or timed-out files are a distinct outcome. If a file needs permanent redaction, that is a Cases job when the org is entitled.
Accountability: export a body-free DPIA pack (prevented leaks, would-have-leaked, coaching). No raw CPR.
Related articles
Still need a hand?