# Installation manual Zivver add-in for OWA and the new Outlook

This installation guide also applies to the new Outlook for Windows. The steps described in this document are the same for both Outlook on the Web (OWA) and the new Outlook.

Each section indicates which products the steps apply to.

## Introduction

OWA New Outlook

Use the Zivver Outlook Web Access Add-in to securely send and receive messages directly from Outlook Web Access (OWA) and the new Outlook. This manual describes how to install the add-in in Exchange Online, which is part of Microsoft 365. The Zivver OWA add-in is available for Exchange Online only.

In this document, we will use the labels OWA and New Outlook to indicate which product a chapter or section applies to:

- **OWA** means this section only applies to the Outlook Web Access add-in, which is used in the web browser version of Outlook ( [https://outlook.office.com](https://outlook.office.com/)).
- **New Outlook** means this section only applies to the new Outlook for Windows.
- **OWA New Outlook** means this section applies to both the Outlook Web Access add-in and the new Outlook for Windows.

In some sections, specific steps or settings apply only to one of the products. In those cases, the label will be shown next to the step or setting.

As of OWA add-in version 6, Zivver uses a new versioning method, consistent with our other integrations. As a result, you will now see version numbers like **3.xxx.x** instead of 6.x.x when viewing the version number in the Zivver side pane.

## Technical requirements

OWA New Outlook

You can install the Zivver OWA add-in in Exchange Online. To use the OWA add-in, the following requirements must be met:

- Use Exchange Online.
- Users’ workstations (Windows or Mac) must have the latest General Availability (GA) or Stable version of one of the following modern browsers installed:
  - Microsoft Edge (Chromium-based) — recommended
  - Google Chrome / Chromium (for Android/iOS) — recommended
  - Mozilla Firefox
  - Apple Safari (for iOS)
- Cookies must be allowed in the browser for the exact URLs listed below:
  - [*].office.com
  - [*].office365.com
  - [*].cloud.microsoft
  - [*].zivver.com

_The Zivver add-in stores the user’s active session in `LocalStorage`. Blocking cookies for these domains will cause users to log in after every page refresh._
- Pop-ups must be allowed in the browser for the exact URLs listed below:
  - [*].office.com
  - [*].office365.com
  - [*].cloud.microsoft
  - [*].zivver.com

_The Zivver add-in uses pop-ups for user authentication. Blocking pop-ups for these domains will prevent users from logging in to Zivver._
- Offline mode must be disabled in the new Outlook.
- The Exchange policy that blocks downloading attachments in Outlook must be disabled (this is the default setting).
- An Entra ID admin account with Global Administrator privileges.
- A Zivver administrator account.

## Limitations

The **Start mail merge** function is not supported in combination with Zivver. Using this function will result in sending unsecured messages.

## Installation

OWA New Outlook

You can install the Zivver OWA add-in either via the Microsoft 365 admin center or by using PowerShell. Both methods are explained in this manual.

### Deploy and configure the Zivver OWA add-in via the Microsoft 365 admin center

OWA New Outlook

1. Log in to the [Microsoft 365 admin center](https://admin.microsoft.com/AdminPortal/Home#/Settings/AddIns).
2. Click _add_ **Deploy Add-In**.
3. Click **Next**.
4. Select **Upload custom apps** under **Deploy a custom add-in**.
5. Enter `https://owa-v6.zivver.com/manifest.xml` as the URL of the OWA add-in manifest file.

Make sure to include `https://`, even though this is already indicated in the user interface.

6. Click **Upload**.

_The **Configure add-in** screen appears._
7. Choose which users will be assigned the Zivver OWA add-in:
    - **Everyone**
      _All users in your organization can use the add-in. Select this to roll out the add-in to your entire organization, for example, when going live with Zivver._
    - **Specific users/groups**
      _Only specific users or groups can use the add-in. Select this for a pilot or if only some users use OWA._
    - **Just me**
      _Only makes the add-in available for your own admin account. Select this option if you want to test the add-in yourself._
8. Select how the add-in will be deployed to users:
    - **Fixed (Default)**
      _Recommended. The add-in is enabled by default for assigned users and cannot be disabled by them._
    - **Available**
      _Not recommended. The add-in is disabled by default, but assigned users can enable it themselves._
    - **Optional**
      _The add-in is enabled by default, but assigned users can choose to disable it._
9. Click **Deploy**.
10. Review the Microsoft notice and click **Next**.
11. Click **Close**.

_The Zivver OWA add-in is now installed and configured for your Microsoft 365 organization. It may take up to 24 hours for the change to take effect in Exchange Online._
12. Continue with [the steps to give admin consent](https://docs.zivver.com/en/admin/owa/installation-manual.html#give-admin-consent-to-the-required-graph-api-permissions).

### Give admin consent to the required Graph API permissions

OWA New Outlook

The Zivver OWA add-in requires admin consent for your organization to work seamlessly with the [Microsoft Graph API](https://developer.microsoft.com/en-us/graph).

1. Paste the URL below in a text editor:

`https://login.microsoftonline.com/{organization}/adminconsent?client_id=cf4ddb54-53ba-4358-955f-38194b69acd4`
2. Find your Tenant ID in [Entra ID](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/TenantOverview.ReactView?Microsoft_AAD_IAM_legacyAADRedirect=true) and copy it.
3. Replace `{organization}` in the URL from step 1 with the Tenant ID you copied in step 2.
4. Paste the updated link in your browser.
5. Sign in with your Microsoft admin account.
6. Click Accept.

After accepting, you will see a blank white screen (no success message). To confirm, check Microsoft Entra for a new enterprise application named **Zivver OWA V6**.

### Create an Exchange rule for Zivver messages

OWA New Outlook

This rule must be set up to prevent OWA from sending a Zivver message as unencrypted, regular email.

If you do not configure this rule, every recipient will receive both the encrypted Zivver message and a secondary placeholder message with a link to the message on [https://app.zivver.com](https://app.zivver.com/). This happens because the ‘zivver-action: discard’ mail flow rule disposes of the secondary placeholder message in Exchange Online.

1. Log in to the [Exchange admin center](https://admin.exchange.microsoft.com/#/transportrules).
2. Click **Mail flow** in the left pane.
3. Select the **Rules** tab.
4. Click _add_ **Add a rule** > **Create a new rule**.
5. Name the rule `zivver-action: discard`.
6. Under **Apply this rule if**, select **The message headers ...** and the sub-option **matches these text patterns**.
7. Click **Enter text**.

_**specify header name** opens._
8. Enter `zivver-action`, then click **Save**.
9. Click **Enter words**.

_**specify words or phrases** opens._
10. Enter `discard`.
11. Click **Add**.
12. Click **Save**.
13. Under **Do the following**, select **Block the message**, and the sub-option **delete the message without notifying anyone**.
14. Click **Next**.

**Set rule settings** opens.
15. Set **Choose a mode for this rule** to **Enforce**.
16. Set Severity to **Low**.
17. Select **Stop processing more rules**.
18. Set **Match sender address in message** to **Header**.
19. Click **Next**, then click **Finish**.
20. Wait a few seconds, then click **Done**.

_You can now set the priority._
21. Select the new rule.
22. Enable the rule.
23. Click **Edit**.

_**zivver-action: discard** opens._
24. Click **Settings**.
25. Set the priority of the `zivver-action: discard` rule to `0`.

_A mail flow rule has now been created to prevent Zivver messages from being sent as unencrypted, regular email._
26. Click **Save**, then click **Done**.

## Required additional settings

OWA New Outlook

### Enable Inbound Direct Delivery

OWA New Outlook

Inbound Direct Delivery (IDD) allows your users to read inbound Zivver messages directly from the reading pane instead of opening the Zivver side pane. To enable this feature, follow the procedure described in the [Inbound Direct Delivery manual](https://docs.zivver.com/en/admin/webapp/inbound-direct-delivery.html).

### Allow cookies in Edge/Chrome

OWA

Allow cookies in the browser for the exact URLs listed below:

See [Allow cookies in Edge/Chrome with Intune](https://docs.zivver.com/en/admin/owa/allow-cookies.html) for instructions on how to allow cookies with Intune.
- [*].office.com
- [*].office365.com
- [*].cloud.microsoft
- [*].zivver.com

_The Zivver add-in stores the user’s active session in `LocalStorage`. Blocking cookies for these domains will cause users to be logged out after every page refresh._

### Allow pop-ups in Edge/Chrome

OWA

Allow pop-ups in the browser for the exact URLs listed below:

See [Allow pop-ups in Edge/Chrome with Intune](https://docs.zivver.com/en/admin/owa/allow-pop-ups.html) for instructions on how to allow pop-ups with Intune.
- [*].office.com
- [*].office365.com
- [*].cloud.microsoft
- [*].zivver.com

_The Zivver add-in uses pop-ups to log users in. Blocking pop-ups for these domains will prevent users from being able to log in to Zivver._

### Configure Exempt Domains

OWA New Outlook

Configure [Exempt Domains from scanning during sending](https://docs.zivver.com/en/admin/owa/exempted-domains.html) to exclude internal domains from Smart Classification.

### Add-in behavior

OWA New Outlook

Configure **Automatically use Zivver when a business rule recommends it** to be set to **On, Mandatory** on the [Add-in Settings page](https://app.zivver.com/organization/plugin-settings). Read more about [Outlook Web Access Add-in integration settings](https://docs.zivver.com/en/admin/webapp/integration-owa-webapp.html).

### Trusted websites in Internet Options

OWA

For Windows users only.

Add the following locations to the **Trusted sites** zone of **Internet Options**:

See [Configure trusted websites with Intune](https://docs.zivver.com/en/admin/owa/configure-trusted-sites.html) for instructions on how to configure trusted websites with Intune.
1. Open the **Control panel**.
2. Click **Network and Internet**.
3. Click **Internet Options**.
4. Click the **Security** tab.
5. Click **Trusted websites**.
6. Click the **Websites** button.
7. Add these URLs as trusted websites:
   - Zivver OWA add-in: `https://owa-v6.zivver.com`  
   - Zivver OWA add-in: `https://owa-v7.zivver.com`  
   - Zivver WebApp: `https://app.zivver.com`  
   - OWA: `https://outlook.office.com`  
   - OWA: `https://outlook.cloud.microsoft`
8. Click **Close**.
9. Click **OK**.

### macOS Safari privacy settings

OWA

For macOS users only.

1. In **Settings** > **Privacy**, make sure “Prevent cross-site tracking” is unchecked.
2. In **Settings** > **Privacy**, make sure “Block all cookies” is unchecked.
3. In **Websites** > **Pop-up windows**, make sure “outlook.office.com” is allowed.
4. In **Websites** > **Pop-up windows**, make sure “outlook.cloud.microsoft” is allowed.

### Disable Offline Mode

New Outlook

In the New Outlook, users can turn on Offline mode, which causes sent messages to be stored in the Outbox. To avoid this issue, follow the steps below to disable the option for Offline mode in the New Outlook settings.

Please be aware that there are scenarios where disabling Offline mode in the OWA mailbox policy does not work.

**Prerequisites**  
- Exchange Online admin permissions.  
- PowerShell is installed on your machine.  
- ExchangeOnlineManagement module is installed in PowerShell on your machine.

**Procedure**  
1. Open PowerShell.  
2. Run the following command to connect to Exchange Online:

```powershell
Connect-ExchangeOnline
```

3. Run the following command to list all existing OWA mailbox policies:

```powershell
Get-OwaMailboxPolicy | Format-Table Name, Identity
```

4. Run the following command to disable Offline Mode for the OWA mailbox policy:

```powershell
Set-OwaMailboxPolicy -Identity "<policy_name>" -OfflineEnabledWin $false
```

5. Run the following command to verify that Offline Mode is disabled:

```powershell
Get-OwaMailboxPolicy -Identity "<policy_name>" | Format-Table Name, OfflineEnabledWin
```

6. Run the following command to disconnect from Exchange Online:

```powershell
Disconnect-ExchangeOnline
```

## Verify the installation was successful

OWA New Outlook

It may take up to 24 hours for the above changes to be implemented in Exchange Online.

1. Click **New** to create a new message.
2. Set up a message with a recipient, subject, and body as usual.  
3. Click the Zivver icon.

If the Zivver icon is not visible, click the three dots in the Outlook toolbar at the top of your screen and click the Zivver link in the menu.

4. Log in to Zivver if you’re not logged in automatically.
5. Turn on **Secure mail**.
6. Click **Recipient verification**.
7. Complete the recipient verification where necessary.
8. Click **Apply**.
9. Click **Send** to send the message.

_You have now verified the installation was successful._

### Remove the Zivver OWA Add-in from Microsoft 365 admin center

OWA New Outlook

If you want to remove the Zivver add-in, follow these steps to uninstall it from the **Microsoft 365 admin center**:

1. Log in to the [Microsoft 365 admin center](https://admin.microsoft.com/AdminPortal/Home#/Settings/AddIns).
2. Select **Zivver**.
3. Scroll down on the Zivver side pane and click **Delete add-in** at the bottom of the side pane.
4. Confirm by clicking **Delete**.

### Remove the Zivver Exchange rule

OWA New Outlook

To remove the Zivver Exchange rule, follow these steps in the **Exchange admin center**:

1. Log in to the [Exchange admin center](https://admin.exchange.microsoft.com/#/transportrules).
2. Click **Mail flow** in the left-side pane.
3. Select the **Rules** tab.
4. Select the mail flow rule **zivver-action: discard**.
5. Delete the rule by clicking the _delete_ icon.
