Microsoft 365

Control the new Outlook for Windows rollout with policies and toggles

The admin controls for new Outlook for Windows: hide the toggle, stop automatic migration, block the app or mailbox access, and migrate on your own schedule before the March 2027 opt-out.

13 min read
On this page

You control the new Outlook for Windows rollout through four independent layers: policies in classic Outlook (the Try the new Outlook toggle, automatic migration and admin-controlled migration), the app package on Windows, Exchange Online mailbox access, and mailbox policies that shape the new app once it is in use. To hold users on classic Outlook, hide the toggle, disable automatic migration and block mailbox access; to move them, enable admin-controlled migration on your own schedule before the Enterprise opt-out stage starts in March 2027.

Who this is for and what you will have at the end

This guide is for Microsoft 365 administrators and endpoint engineers who need to decide when their users move from classic Outlook to the new Outlook for Windows, and who want that decision enforced rather than left to a toggle. By the end you will have:

  • A clear picture of the migration stages and the dates that apply to Enterprise tenants.
  • A map of every control, which layer it lives in and what it does not cover.
  • Policies or registry values to keep users on classic Outlook while you prepare.
  • A staged migration plan using admin-controlled migration, retry intervals and the classic Outlook toggle in new Outlook.
  • Baseline mailbox policies for the new app.

The migration stages and the current timeline

Microsoft describes three stages:

StageDefault experienceCan users go back to classic?
Opt-inClassic Outlook; users choose Try the new OutlookYes
Opt-outNew Outlook on by default; users are brought into it automaticallyYes
CutoverNew Outlook only; new Microsoft 365 deployments get new OutlookNo

New Outlook reached general availability on August 1, 2024. Microsoft commits to at least 12 months of notice before the opt-out stage reaches managed Enterprise plans, and at least 12 months before cutover reaches production rings. Existing installations of classic Outlook through perpetual and subscription licensing remain supported until at least 2029.

Message center post MC949965 (Toggle to new Outlook), last updated on February 20, 2026, moved the start of the opt-out stage for Enterprise environments from April 2026 to March 2027. GCC High and DoD timelines will be communicated separately. The same post lists users who are not migrated automatically:

  • Users opted out through the automatic migration policy.
  • Users whose Try the new Outlook toggle is hidden by policy.
  • Users on a perpetual licence.
  • Users with an on-premises mailbox account.

Check MC949965 in your own tenant's message center before you finalise dates, because Microsoft updates the timeline there.

The controls at a glance

LayerControlWhat it doesWhat it doesn't do
Classic OutlookHide the "Try the new Outlook" toggle (HideNewOutlookToggle)Removes the toggle from classic OutlookDoesn't stop the app being installed or a mailbox being added
Classic OutlookManage user setting for new Outlook automatic migration (NewOutlookMigrationUserSetting)Allows or blocks automatic migration and locks the user settingDoesn't apply to admin-controlled migration
Classic OutlookAdmin-Controlled Migration to New Outlook (DoNewOutlookAutoMigration)Moves users to new Outlook in three nudgesRuns once unless you set the interval policy
Classic OutlookInterval between new Outlook migration attempts (NewOutlookAutoMigrationRetryIntervals)Restarts migration after users switch backIgnored unless admin-controlled migration is on
WindowsRemove the Microsoft.OutlookForWindows package, block preinstall on Windows 10Removes or prevents the app on devicesDoesn't stop Store installs if the Store is open
Exchange OnlineOneWinNativeOutlookEnabled on Set-CASMailbox or Set-OwaMailboxPolicyBlocks work or school mailboxes in new OutlookDoesn't hide the toggle in classic Outlook
Exchange OnlineHideClassicOutlookToggleOut on Set-OwaMailboxPolicyHides the toggle back to classic inside new OutlookDoesn't install the app or migrate anyone

Classic Outlook group policies don't carry over. All ADMX templates and most cloud policies apply only to classic Outlook; new Outlook is configured mainly through Outlook on the web mailbox policies and a small set of cloud policies.

Prerequisites

  • Microsoft 365 Apps on a supported channel. The toggle policy is available from Current Channel Version 2304 (Build 16327.20214), Monthly Enterprise Channel Version 2303 (Build 16227.20318) and Semi-Annual Enterprise Channel Build 16731.20504. Admin-controlled migration and its retry-interval policy need Current Channel Version 2406 (Build 16.0.17830.20138) or later; Microsoft said they were expected in Monthly Enterprise Channel from September 2024.
  • Access to the Microsoft 365 Apps admin center (config.office.com) for cloud policy, or the latest Office ADMX templates for Group Policy or Intune administrative templates.
  • Exchange Online PowerShell with permissions for Outlook on the web mailbox policies. If connecting fails, see Connect-ExchangeOnline errors and fixes.
  • Mailboxes in Exchange Online. New Outlook isn't supported for on-premises mailboxes, so in hybrid organizations target only cloud users with migration policies.

Step 1: Keep users on classic Outlook while you prepare

Hide the toggle in classic Outlook

The cleanest method is cloud policy. In the Microsoft 365 Apps admin center, go to Customization > Policy Management, select Create, search for Hide the "Try the new Outlook" toggle in Outlook and enable it. Scope the policy to the groups that should stay on classic Outlook.

The registry equivalent is the per-user value HideNewOutlookToggle under HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\General; 1 hides the toggle and 0 shows it. Writing the same value as 1 under the policies key stops users changing it. The script below creates each key only if it is missing; don't use New-Item -Force on an existing registry key, because it recreates the key and deletes the values already in it.

foreach ($path in 'HKCU:\Software\Microsoft\Office\16.0\Outlook\Options\General',
                  'HKCU:\Software\Policies\Microsoft\office\16.0\outlook\options\general') {
    if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
    New-ItemProperty -Path $path -Name 'HideNewOutlookToggle' -PropertyType DWord -Value 1 -Force
}

If a user already switched to new Outlook and the toggle is then hidden, launching the classic Outlook icon returns them to classic Outlook. Launching the new Outlook icon still opens new Outlook, because only classic Outlook reads this value, and the switch-back logic runs when the value is read, typically after a restart.

Turn off automatic migration

Set the Manage user setting for new Outlook automatic migration policy to disabled. Through the registry:

$path = 'HKCU:\Software\Policies\Microsoft\office\16.0\outlook\preferences'
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'NewOutlookMigrationUserSetting' -PropertyType DWord -Value 0 -Force

0 blocks automatic migration and prevents users from changing the setting, 1 allows it and locks it on, and leaving it unset lets users manage it themselves (enabled by default). This policy doesn't affect migrations you start with the admin-controlled migration policy.

Step 2: Control the app on Windows devices

Hiding the toggle doesn't remove the app. How it arrives depends on the Windows version.

Windows 11. Builds later than 23H2 have new Outlook preinstalled for all users, and there is currently no way to block that installation. Remove the provisioned package after the update; Microsoft states that Windows updates won't reinstall it afterwards:

Remove-AppxProvisionedPackage -AllUsers -Online -PackageName (Get-AppxPackage Microsoft.OutlookForWindows).PackageFullName

On devices without the March 2024 non-security preview (or a later cumulative update) for Windows 11 version 23H2, also remove the OutlookUpdate value under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe.

Windows 10. The app was installed automatically with the January 28, 2025 optional release and the February 11, 2025 security update. To prevent the installation, create a REG_SZ value named BlockedOobeUpdaters with the data ["MS_Outlook"]:

$path = 'HKLM:\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe'
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'BlockedOobeUpdaters' -PropertyType String -Value '["MS_Outlook"]' -Force

User installs. When users installed new Outlook themselves, for example through the toggle, remove it with the per-user cmdlet:

Remove-AppxPackage -AllUsers -Package (Get-AppxPackage Microsoft.OutlookForWindows).PackageFullName

Mail and Calendar. Windows Mail and Calendar reached end of support on December 31, 2024, and active users are being switched to new Outlook. To close that path, remove the microsoft.windowscommunicationsapps package, and use Set-CASMailbox -UniversalOutlookEnabled $false to block work accounts from those apps.

Microsoft Store. Block or restrict Store access with your normal Windows Store configuration if you don't want users downloading the app.

A Start menu pin can appear even when the app isn't installed; selecting it installs the app. To check whether the app actually ran for a user, look for %localappdata%\Microsoft\Olk\logs.

Step 3: Block mailbox access as the final control

Because there are several ways to get the app, Microsoft describes the Exchange Online setting as the final block: it prevents work or school mailboxes being added to new Outlook regardless of where the app came from. The default value of OneWinNativeOutlookEnabled is blank ($null), which behaves as $true.

For individual mailboxes:

Set-CASMailbox -Identity colin@contoso.com -OneWinNativeOutlookEnabled $false
Get-CASMailbox -Identity colin@contoso.com | Format-List Name,OneWinNativeOutlookEnabled

For everyone covered by the default Outlook on the web mailbox policy, which includes future mailboxes:

Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -OneWinNativeOutlookEnabled $false
Get-OwaMailboxPolicy | Format-Table Name,OneWinNativeOutlookEnabled

Three details matter:

  • If OWAEnabled is False on a mailbox, new Outlook access is also blocked, whatever OneWinNativeOutlookEnabled says.
  • Access to shared mailboxes and public folders in new Outlook follows the Outlook on the web mailbox policy, not the CAS mailbox setting.
  • A user already using new Outlook when you block access sees the account disabled in the app. A user who tries the toggle after you block access gets an error.

This setting does not hide the toggle in classic Outlook. Combine it with Step 1 so users don't see an option that fails.

Step 4: Migrate on your own schedule

When a pilot group is ready, use Admin-Controlled Migration to New Outlook rather than waiting for the opt-out stage. The toggle must be visible for these users, so remove any HideNewOutlookToggle policy that targets them first.

With the policy set to 1, classic Outlook installs new Outlook in the background on its next launch if needed, then moves users across three sessions: a teaching callout, a business bar warning that the next start switches them, and finally a prompt after which the next launch opens new Outlook. Users can toggle back at any time.

$path = 'HKCU:\Software\Policies\Microsoft\Office\16.0\Outlook\Options\General'
if (-not (Test-Path $path)) { New-Item -Path $path -Force | Out-Null }
New-ItemProperty -Path $path -Name 'DoNewOutlookAutoMigration' -PropertyType DWord -Value 1 -Force
New-ItemProperty -Path $path -Name 'NewOutlookAutoMigrationRetryIntervals' -PropertyType DWord -Value 30 -Force

The migration runs once. NewOutlookAutoMigrationRetryIntervals restarts it after users switch back: 0 or not set means never, 1 means every launch of classic Outlook shows the blocking prompt, and a value from 2 to 99000 restarts migration that many days after the user returned to classic. Setting DoNewOutlookAutoMigration to 0 or deleting it stops migration; users already in new Outlook stay there but keep the toggle back.

GoalDoNewOutlookAutoMigrationRetry intervalHideClassicOutlookToggleOut
Everyone tries new Outlook once1Not setNot set
Re-prompt every 30 days130Not set
Prompt at every classic launch11Not set
Move users with no way back11$true
Stop migrating0Not setNot set

To remove the toggle back to classic Outlook inside new Outlook, set the mailbox policy:

Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -HideClassicOutlookToggleOut $true

For new starters who have both apps installed, the per-user value UseNewOutlook set to 1 under HKEY_CURRENT_USER\Software\Microsoft\office\16.0\outlook\preferences switches them to new Outlook when they open classic Outlook. Microsoft also suggests pinning new Outlook to the taskbar and making it the default handler for .eml, .msg, .ics and mailto.

In the Microsoft 365 admin center, Health > Product Feedback, filtered to New Outlook for Windows, shows what pilot users report when they switch back.

Step 5: Set baseline policies for new Outlook

Before broad rollout, apply the mailbox policies that replace your classic Outlook GPOs. Useful starting points from Microsoft's policy guidance:

Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -PersonalAccountsEnabled $false
Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -AllowedOrganizationAccountDomains 'contoso.com','fabrikam.com'
  • PersonalAccountsEnabled $false stops users adding personal accounts, and disables any already added.
  • AllowedOrganizationAccountDomains limits which work account domains can be added.
  • OfflineEnabledWin allows or blocks offline use of new Outlook.
  • OutlookDataFile limits or disables .pst support, which is enabled by default. New Outlook enforces only the primary account's setting.
  • The Require the Primary Account to match the Windows signed-in account policy, under Apps > Policies for Microsoft 365 apps in the Intune admin center, makes the user's work account the primary account so app-wide settings follow your policy.

Most Outlook on the web mailbox policies apply to both Outlook on the web and new Outlook, so you can't enable a feature in one but not the other.

Verification

  1. On a pilot device, open classic Outlook and confirm the toggle is present or hidden as intended for that user's group.
  2. Run Get-AppxPackage Microsoft.OutlookForWindows as the user. It should return nothing on devices where you removed the app.
  3. Run Get-CASMailbox -Identity <user> | Format-List OWAEnabled,OneWinNativeOutlookEnabled and Get-OwaMailboxPolicy | Format-Table Name,OneWinNativeOutlookEnabled,HideClassicOutlookToggleOut to confirm the Exchange side.
  4. For migration pilots, check that users see the callout on the first launch after the policy applies, and that DoNewOutlookAutoMigration is present under the policies key.

Troubleshooting

Users report that new Outlook appeared after a Windows update. On Windows 11 later than 23H2 this is expected. Remove the provisioned package; Windows updates won't reinstall it.

Pilot users never see the migration prompts. The toggle is hidden for them. Admin-controlled migration requires the toggle to be visible. Also confirm the build meets the minimum version.

A user's account shows as disabled in new Outlook. OneWinNativeOutlookEnabled is $false on the mailbox or its Outlook on the web mailbox policy, or OWAEnabled is $false.

Users can open their own mailbox in new Outlook but not a shared mailbox. Shared mailbox access follows the Outlook on the web mailbox policy, and both the user and the shared mailbox need access.

Classic Outlook policies aren't applied in new Outlook. That is by design. Use Microsoft's guide to map classic Outlook policies to new Outlook and apply the equivalent mailbox or cloud policies.

Add-ins don't load in new Outlook. COM add-ins aren't supported in new Outlook; inventory them and move to web add-ins before migration.

Checklist

  • MC949965 checked in your tenant; opt-out date and exclusions recorded in the plan.
  • Groups defined for users who stay on classic Outlook and users in each migration wave.
  • Toggle hidden and automatic migration disabled for the hold group.
  • App removed or blocked on devices where it must not run; Mail and Calendar and Store paths closed.
  • OneWinNativeOutlookEnabled set where mailbox access must be blocked.
  • Admin-controlled migration and retry intervals configured per wave; toggle visible for those users.
  • Baseline Outlook on the web mailbox policies applied and classic GPOs mapped.
  • COM add-in inventory complete and web add-in replacements tested.

References

Questions people ask

When will new Outlook become the default for enterprise users?

Microsoft 365 message center post MC949965 moved the opt-out stage for Enterprise environments from April 2026 to March 2027. In opt-out, new Outlook is on by default but users can still switch back. Microsoft commits to at least 12 months of notice before the later cutover stage, and existing classic Outlook installations stay supported until at least 2029.

How do I stop users switching to the new Outlook?

Hide the Try the new Outlook toggle in classic Outlook with the cloud policy or the HideNewOutlookToggle registry value, and set the Manage user setting for new Outlook automatic migration policy (NewOutlookMigrationUserSetting) to 0. To stop work mailboxes being used in the app at all, set OneWinNativeOutlookEnabled to $false with Set-CASMailbox or Set-OwaMailboxPolicy.

Does hiding the toggle block new Outlook completely?

No. The toggle setting only affects classic Outlook. Users can still get the app preinstalled with Windows 11, from the Microsoft Store or from Mail and Calendar. The Exchange Online OneWinNativeOutlookEnabled setting is the final block because it stops work or school mailboxes being added regardless of how the app was installed.

Can I uninstall new Outlook from Windows 11 devices?

Yes. Run Remove-AppxProvisionedPackage with the Microsoft.OutlookForWindows package name. Microsoft states that Windows updates won't reinstall it after the provisioned package is removed. Use Remove-AppxPackage for copies users already installed.

New Outlook for WindowsOutlookMicrosoft 365 AppsGroup PolicyExchange Online
  1. Fix Microsoft 365 email going to Junk by reading SFV, CAT and compauth

    Work out why Exchange Online delivered a message to Junk Email from its anti-spam headers, then apply the fix that matches the component that filtered it.

    Microsoft 36513 min read
  2. Full Access, Send As and Send on Behalf in Exchange Online with PowerShell

    Grant, remove and audit the three mailbox delegation permissions in Exchange Online with PowerShell, control Outlook automapping, and fix the errors delegates hit most often.

    Microsoft 3659 min read
  3. Outlook Autodiscover problems with Microsoft 365: DNS checks and fixes

    Fix Outlook profiles that can't find an Exchange Online mailbox: check the Autodiscover CNAME, root domain responses, cached URLs, registry and Group Policy settings.

    Microsoft 36511 min read