You control the new Outlook for Windows rollout through four independent layers: policies in classic Outlook (the Try the new Outlook toggle, automatic migration and admin-controlled migration), the app package on Windows, Exchange Online mailbox access, and mailbox policies that shape the new app once it is in use. To hold users on classic Outlook, hide the toggle, disable automatic migration and block mailbox access; to move them, enable admin-controlled migration on your own schedule before the Enterprise opt-out stage starts in March 2027.
Who this is for and what you will have at the end
This guide is for Microsoft 365 administrators and endpoint engineers who need to decide when their users move from classic Outlook to the new Outlook for Windows, and who want that decision enforced rather than left to a toggle. By the end you will have:
- A clear picture of the migration stages and the dates that apply to Enterprise tenants.
- A map of every control, which layer it lives in and what it does not cover.
- Policies or registry values to keep users on classic Outlook while you prepare.
- A staged migration plan using admin-controlled migration, retry intervals and the classic Outlook toggle in new Outlook.
- Baseline mailbox policies for the new app.
The migration stages and the current timeline
Microsoft describes three stages:
| Stage | Default experience | Can users go back to classic? |
|---|---|---|
| Opt-in | Classic Outlook; users choose Try the new Outlook | Yes |
| Opt-out | New Outlook on by default; users are brought into it automatically | Yes |
| Cutover | New Outlook only; new Microsoft 365 deployments get new Outlook | No |
New Outlook reached general availability on August 1, 2024. Microsoft commits to at least 12 months of notice before the opt-out stage reaches managed Enterprise plans, and at least 12 months before cutover reaches production rings. Existing installations of classic Outlook through perpetual and subscription licensing remain supported until at least 2029.
Message center post MC949965 (Toggle to new Outlook), last updated on February 20, 2026, moved the start of the opt-out stage for Enterprise environments from April 2026 to March 2027. GCC High and DoD timelines will be communicated separately. The same post lists users who are not migrated automatically:
- Users opted out through the automatic migration policy.
- Users whose Try the new Outlook toggle is hidden by policy.
- Users on a perpetual licence.
- Users with an on-premises mailbox account.
Check MC949965 in your own tenant's message center before you finalise dates, because Microsoft updates the timeline there.
The controls at a glance
| Layer | Control | What it does | What it doesn't do |
|---|---|---|---|
| Classic Outlook | Hide the "Try the new Outlook" toggle (HideNewOutlookToggle) | Removes the toggle from classic Outlook | Doesn't stop the app being installed or a mailbox being added |
| Classic Outlook | Manage user setting for new Outlook automatic migration (NewOutlookMigrationUserSetting) | Allows or blocks automatic migration and locks the user setting | Doesn't apply to admin-controlled migration |
| Classic Outlook | Admin-Controlled Migration to New Outlook (DoNewOutlookAutoMigration) | Moves users to new Outlook in three nudges | Runs once unless you set the interval policy |
| Classic Outlook | Interval between new Outlook migration attempts (NewOutlookAutoMigrationRetryIntervals) | Restarts migration after users switch back | Ignored unless admin-controlled migration is on |
| Windows | Remove the Microsoft.OutlookForWindows package, block preinstall on Windows 10 | Removes or prevents the app on devices | Doesn't stop Store installs if the Store is open |
| Exchange Online | OneWinNativeOutlookEnabled on Set-CASMailbox or Set-OwaMailboxPolicy | Blocks work or school mailboxes in new Outlook | Doesn't hide the toggle in classic Outlook |
| Exchange Online | HideClassicOutlookToggleOut on Set-OwaMailboxPolicy | Hides the toggle back to classic inside new Outlook | Doesn't install the app or migrate anyone |
Classic Outlook group policies don't carry over. All ADMX templates and most cloud policies apply only to classic Outlook; new Outlook is configured mainly through Outlook on the web mailbox policies and a small set of cloud policies.
Prerequisites
- Microsoft 365 Apps on a supported channel. The toggle policy is available from Current Channel Version 2304 (Build 16327.20214), Monthly Enterprise Channel Version 2303 (Build 16227.20318) and Semi-Annual Enterprise Channel Build 16731.20504. Admin-controlled migration and its retry-interval policy need Current Channel Version 2406 (Build 16.0.17830.20138) or later; Microsoft said they were expected in Monthly Enterprise Channel from September 2024.
- Access to the Microsoft 365 Apps admin center (config.office.com) for cloud policy, or the latest Office ADMX templates for Group Policy or Intune administrative templates.
- Exchange Online PowerShell with permissions for Outlook on the web mailbox policies. If connecting fails, see Connect-ExchangeOnline errors and fixes.
- Mailboxes in Exchange Online. New Outlook isn't supported for on-premises mailboxes, so in hybrid organizations target only cloud users with migration policies.
Step 1: Keep users on classic Outlook while you prepare
Hide the toggle in classic Outlook
The cleanest method is cloud policy. In the Microsoft 365 Apps admin center, go to Customization > Policy Management, select Create, search for Hide the "Try the new Outlook" toggle in Outlook and enable it. Scope the policy to the groups that should stay on classic Outlook.
The registry equivalent is the per-user value HideNewOutlookToggle under HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\General; 1 hides the toggle and 0 shows it. Writing the same value as 1 under the policies key stops users changing it. The script below creates each key only if it is missing; don't use New-Item -Force on an existing registry key, because it recreates the key and deletes the values already in it.
foreach ($path in 'HKCU:\Software\Microsoft\Office\16.0\Outlook\Options\General',
'HKCU:\Software\Policies\Microsoft\office\16.0\outlook\options\general') {
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'HideNewOutlookToggle' -PropertyType DWord -Value 1 -Force
}If a user already switched to new Outlook and the toggle is then hidden, launching the classic Outlook icon returns them to classic Outlook. Launching the new Outlook icon still opens new Outlook, because only classic Outlook reads this value, and the switch-back logic runs when the value is read, typically after a restart.
Turn off automatic migration
Set the Manage user setting for new Outlook automatic migration policy to disabled. Through the registry:
$path = 'HKCU:\Software\Policies\Microsoft\office\16.0\outlook\preferences'
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'NewOutlookMigrationUserSetting' -PropertyType DWord -Value 0 -Force0 blocks automatic migration and prevents users from changing the setting, 1 allows it and locks it on, and leaving it unset lets users manage it themselves (enabled by default). This policy doesn't affect migrations you start with the admin-controlled migration policy.
Step 2: Control the app on Windows devices
Hiding the toggle doesn't remove the app. How it arrives depends on the Windows version.
Windows 11. Builds later than 23H2 have new Outlook preinstalled for all users, and there is currently no way to block that installation. Remove the provisioned package after the update; Microsoft states that Windows updates won't reinstall it afterwards:
Remove-AppxProvisionedPackage -AllUsers -Online -PackageName (Get-AppxPackage Microsoft.OutlookForWindows).PackageFullNameOn devices without the March 2024 non-security preview (or a later cumulative update) for Windows 11 version 23H2, also remove the OutlookUpdate value under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe.
Windows 10. The app was installed automatically with the January 28, 2025 optional release and the February 11, 2025 security update. To prevent the installation, create a REG_SZ value named BlockedOobeUpdaters with the data ["MS_Outlook"]:
$path = 'HKLM:\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe'
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'BlockedOobeUpdaters' -PropertyType String -Value '["MS_Outlook"]' -ForceUser installs. When users installed new Outlook themselves, for example through the toggle, remove it with the per-user cmdlet:
Remove-AppxPackage -AllUsers -Package (Get-AppxPackage Microsoft.OutlookForWindows).PackageFullNameMail and Calendar. Windows Mail and Calendar reached end of support on December 31, 2024, and active users are being switched to new Outlook. To close that path, remove the microsoft.windowscommunicationsapps package, and use Set-CASMailbox -UniversalOutlookEnabled $false to block work accounts from those apps.
Microsoft Store. Block or restrict Store access with your normal Windows Store configuration if you don't want users downloading the app.
A Start menu pin can appear even when the app isn't installed; selecting it installs the app. To check whether the app actually ran for a user, look for %localappdata%\Microsoft\Olk\logs.
Step 3: Block mailbox access as the final control
Because there are several ways to get the app, Microsoft describes the Exchange Online setting as the final block: it prevents work or school mailboxes being added to new Outlook regardless of where the app came from. The default value of OneWinNativeOutlookEnabled is blank ($null), which behaves as $true.
For individual mailboxes:
Set-CASMailbox -Identity colin@contoso.com -OneWinNativeOutlookEnabled $false
Get-CASMailbox -Identity colin@contoso.com | Format-List Name,OneWinNativeOutlookEnabledFor everyone covered by the default Outlook on the web mailbox policy, which includes future mailboxes:
Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -OneWinNativeOutlookEnabled $false
Get-OwaMailboxPolicy | Format-Table Name,OneWinNativeOutlookEnabledThree details matter:
- If
OWAEnabledisFalseon a mailbox, new Outlook access is also blocked, whateverOneWinNativeOutlookEnabledsays. - Access to shared mailboxes and public folders in new Outlook follows the Outlook on the web mailbox policy, not the CAS mailbox setting.
- A user already using new Outlook when you block access sees the account disabled in the app. A user who tries the toggle after you block access gets an error.
This setting does not hide the toggle in classic Outlook. Combine it with Step 1 so users don't see an option that fails.
Step 4: Migrate on your own schedule
When a pilot group is ready, use Admin-Controlled Migration to New Outlook rather than waiting for the opt-out stage. The toggle must be visible for these users, so remove any HideNewOutlookToggle policy that targets them first.
With the policy set to 1, classic Outlook installs new Outlook in the background on its next launch if needed, then moves users across three sessions: a teaching callout, a business bar warning that the next start switches them, and finally a prompt after which the next launch opens new Outlook. Users can toggle back at any time.
$path = 'HKCU:\Software\Policies\Microsoft\Office\16.0\Outlook\Options\General'
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'DoNewOutlookAutoMigration' -PropertyType DWord -Value 1 -Force
New-ItemProperty -Path $path -Name 'NewOutlookAutoMigrationRetryIntervals' -PropertyType DWord -Value 30 -ForceThe migration runs once. NewOutlookAutoMigrationRetryIntervals restarts it after users switch back: 0 or not set means never, 1 means every launch of classic Outlook shows the blocking prompt, and a value from 2 to 99000 restarts migration that many days after the user returned to classic. Setting DoNewOutlookAutoMigration to 0 or deleting it stops migration; users already in new Outlook stay there but keep the toggle back.
| Goal | DoNewOutlookAutoMigration | Retry interval | HideClassicOutlookToggleOut |
|---|---|---|---|
| Everyone tries new Outlook once | 1 | Not set | Not set |
| Re-prompt every 30 days | 1 | 30 | Not set |
| Prompt at every classic launch | 1 | 1 | Not set |
| Move users with no way back | 1 | 1 | $true |
| Stop migrating | 0 | Not set | Not set |
To remove the toggle back to classic Outlook inside new Outlook, set the mailbox policy:
Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -HideClassicOutlookToggleOut $trueFor new starters who have both apps installed, the per-user value UseNewOutlook set to 1 under HKEY_CURRENT_USER\Software\Microsoft\office\16.0\outlook\preferences switches them to new Outlook when they open classic Outlook. Microsoft also suggests pinning new Outlook to the taskbar and making it the default handler for .eml, .msg, .ics and mailto.
In the Microsoft 365 admin center, Health > Product Feedback, filtered to New Outlook for Windows, shows what pilot users report when they switch back.
Step 5: Set baseline policies for new Outlook
Before broad rollout, apply the mailbox policies that replace your classic Outlook GPOs. Useful starting points from Microsoft's policy guidance:
Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -PersonalAccountsEnabled $false
Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -AllowedOrganizationAccountDomains 'contoso.com','fabrikam.com'PersonalAccountsEnabled $falsestops users adding personal accounts, and disables any already added.AllowedOrganizationAccountDomainslimits which work account domains can be added.OfflineEnabledWinallows or blocks offline use of new Outlook.OutlookDataFilelimits or disables.pstsupport, which is enabled by default. New Outlook enforces only the primary account's setting.- The Require the Primary Account to match the Windows signed-in account policy, under Apps > Policies for Microsoft 365 apps in the Intune admin center, makes the user's work account the primary account so app-wide settings follow your policy.
Most Outlook on the web mailbox policies apply to both Outlook on the web and new Outlook, so you can't enable a feature in one but not the other.
Verification
- On a pilot device, open classic Outlook and confirm the toggle is present or hidden as intended for that user's group.
- Run
Get-AppxPackage Microsoft.OutlookForWindowsas the user. It should return nothing on devices where you removed the app. - Run
Get-CASMailbox -Identity <user> | Format-List OWAEnabled,OneWinNativeOutlookEnabledandGet-OwaMailboxPolicy | Format-Table Name,OneWinNativeOutlookEnabled,HideClassicOutlookToggleOutto confirm the Exchange side. - For migration pilots, check that users see the callout on the first launch after the policy applies, and that
DoNewOutlookAutoMigrationis present under the policies key.
Troubleshooting
Users report that new Outlook appeared after a Windows update. On Windows 11 later than 23H2 this is expected. Remove the provisioned package; Windows updates won't reinstall it.
Pilot users never see the migration prompts. The toggle is hidden for them. Admin-controlled migration requires the toggle to be visible. Also confirm the build meets the minimum version.
A user's account shows as disabled in new Outlook. OneWinNativeOutlookEnabled is $false on the mailbox or its Outlook on the web mailbox policy, or OWAEnabled is $false.
Users can open their own mailbox in new Outlook but not a shared mailbox. Shared mailbox access follows the Outlook on the web mailbox policy, and both the user and the shared mailbox need access.
Classic Outlook policies aren't applied in new Outlook. That is by design. Use Microsoft's guide to map classic Outlook policies to new Outlook and apply the equivalent mailbox or cloud policies.
Add-ins don't load in new Outlook. COM add-ins aren't supported in new Outlook; inventory them and move to web add-ins before migration.
Checklist
- MC949965 checked in your tenant; opt-out date and exclusions recorded in the plan.
- Groups defined for users who stay on classic Outlook and users in each migration wave.
- Toggle hidden and automatic migration disabled for the hold group.
- App removed or blocked on devices where it must not run; Mail and Calendar and Store paths closed.
OneWinNativeOutlookEnabledset where mailbox access must be blocked.- Admin-controlled migration and retry intervals configured per wave; toggle visible for those users.
- Baseline Outlook on the web mailbox policies applied and classic GPOs mapped.
- COM add-in inventory complete and web add-in replacements tested.
References
- Stages of migration to new Outlook for Windows
- Control installing and using new Outlook
- Enable or disable access to Outlook for Windows
- Policy for admin-controlled migration to new Outlook for Windows
- Start new users in new Outlook
- Policy management in new Outlook for Windows
- Map classic Outlook policies to new Outlook
- Set-OwaMailboxPolicy
- Set-CASMailbox
- MC949965 - Toggle to new Outlook (message center mirror)