Registry Keys for Office 365 (2013/2016/O365)

A magnifying glass held over an Office 365 brochure, enlarging the Word, Excel, PowerPoint, OneNote, Outlook, Publisher and Access icons.

Registry settings for Microsoft 365 and Office 2013, 2016, 2019 and 2021, collected over years of fixing these machines in the field. Each one lists the exact command to apply it, which branch to write, what it costs you, and how to undo it.

Use the filter. Type a symptom or a value name, such as pst, autodiscover, onedrive or DisablePST, to narrow the list. Tick several settings to collect them into one block you can copy.

Most of what is here is not in Microsoft’s documentation. Badges say where each setting came from, and the ones marked From a Microsoft support case are keys an engineer handed someone on an escalated ticket that were never published.

One thing worth knowing before you start: most write-ups hand you the Software\Policies\Microsoft\Office path. If you are working on a machine with no Group Policy, which is most small environments, you usually want the preference branch instead, and a policy value will be overwritten on the next refresh if a domain ever does appear. Every entry below says which branch it uses and whether a refresh will clobber it.

These change Windows and Office behaviour. Read what a command does before running it, and note the revert on each entry.

Registry Keys for Office 2013/2016

120 settings

AutoDiscover and password prompts

Outlook finding the wrong mailbox, or asking for credentials forever.

DisableAutodiscoverV2Service

Found in the fieldUndocumented

Outlook prompts for credentials in a loop against a newly patched Exchange 2019, or actionable messages / protocol endpoints misbehave.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "DisableAutodiscoverV2Service" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"DisableAutodiscoverV2Service"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
DisableAutodiscoverV2Service
Type
REG_DWORD
What the values mean
  • 0 default - Outlook uses the Autodiscover V2 (REST) service
  • 1 disable the Autodiscover V2 service
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2016 and later (16.0). Reported against Exchange 2019 CU3 as a server-side regression that Microsoft said would be fixed in a later CU - so treat it as a temporary workaround and retest after Exchange patching. It is also exposed through the Outlook 'Disable AutoDiscover' Group Policy as the 'Disable the Autodiscover V2 service' checkbox.
To undo
Set to 0 or delete the value; also clear the Autodiscover cache in %LocalAppData%\Microsoft\Outlook (the *Autodiscover.xml and 16\*.xml / *.json files) and restart Outlook.

What this costs you Disabling V2 stops Outlook reaching the actions protocol endpoint, which breaks actionable messages and some newer REST-based features. Check it is NOT set when diagnosing 'actionable messages render incorrectly' - a stale 1 here is a cause, not a cure.

Source: woshub.com, learn.microsoft.com

Clear cached Autodiscover URL after migration

Found in the field

After a tenant-to-tenant migration (or a mailbox move) Outlook keeps hitting the OLD Autodiscover URL and won't build a new profile.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "ExcludeLastKnownGoodUrl" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ExcludeLastKnownGoodUrl"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
ExcludeLastKnownGoodUrl
Type
REG_DWORD
What the values mean
  • 0 default - Outlook reuses the last Autodiscover URL that worked for the primary account (step 3)
  • 1 never reuse the last known good URL; rediscover every time
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2010 build 14.0.7140.5001 and later (Jaap Wesselius). 16.0 = Office 2016/2019/2021/2024/365, 15.0 = Office 2013.
To undo
Delete the value or set to 0, restart Outlook. Also worth clearing %LocalAppData%\Microsoft\Outlook\*Autodiscover.xml cache files.

What this costs you Costs a little startup time on every launch because the shortcut cache is gone. Best used as a temporary cutover setting - set it for the migration window, remove it afterwards. The only other documented fix is building a fresh Outlook profile.

Source: chicagotech.net, jaapwesselius.com, learn.microsoft.com

Stop Outlook reading Exchange SCP from AD

Found in the field

Mailboxes are in Microsoft 365 but domain-joined PCs still chase the decommissioned on-prem Exchange from Active Directory - slow Outlook start, password prompts, sometimes AD account lockouts.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "ExcludeScpLookup" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ExcludeScpLookup"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
ExcludeScpLookup
Type
REG_DWORD
What the values mean
  • 0 default - domain-joined Outlook does an LDAP query for Autodiscover Service Connection Points (step 5)
  • 1 skip the Active Directory SCP lookup
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2007 onwards; 16.0 for 2016/2019/2021/2024/365, 15.0 for 2013. Only has any effect on domain-joined machines - on a workgroup PC the SCP step never runs anyway.
To undo
Delete the value or set to 0, restart Outlook.

What this costs you Breaks internal discovery for any mailbox still on-premises. There is a server-side alternative that avoids touching every workstation: on the remaining Exchange server run Set-ClientAccessServer -Identity "CAS Name" -AutoDiscoverServiceInternalUri $NULL, which empties the SCP for the whole org - but only after every mailbox has moved.

Source: jaapwesselius.com, portal.smartertools.com, learn.microsoft.com

Feed Outlook a local autodiscover.xml

Vendor documented

We need Outlook to use settings we supply ourselves because public Autodiscover is wrong, hijacked by a tenant, or unavailable during a cutover.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "PreferLocalXML" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"PreferLocalXML"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
PreferLocalXML
Type
REG_DWORD
What the values mean
  • 0 default - the local-XML check happens late (step 8), after the network probes
  • 1 check the local XML file first (step 2 instead of step 8)
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2007 onwards; 16.0 for 2016/2019/2021/2024/365, 15.0 for 2013.
To undo
Delete PreferLocalXML and the per-domain REG_SZ, restart Outlook.

What this costs you PreferLocalXML on its own does nothing. It needs a companion REG_SZ in the SAME key whose NAME is the SMTP domain and whose DATA is the full path to the XML file - e.g. a REG_SZ named contoso.com with data C:\Autodiscover\autodiscover.xml. If the XML goes stale (server rename, cert change, tenant move) Outlook keeps using the wrong settings and nothing in the UI hints why, so document it on the machine. Note a Microsoft moderator on MS Q&A also suggests explicitly setting PreferLocalXML=0 when chasing rogue O365 prompts, i.e. this key being present and set wrongly is itself a cause of symptoms.

Source: portal.smartertools.com, github.com, learn.microsoft.com

Pre-trust an AutoDiscover redirect server

Vendor documented

Every new profile throws 'Allow this website to configure user@contoso.com server settings?' and users click the wrong button or just cancel.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover\RedirectServers" /v "secure.autodiscover.emailsrvr.com" /t REG_SZ /d "" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover\RedirectServers]
"secure.autodiscover.emailsrvr.com"=""
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover\RedirectServers
Value
secure.autodiscover.emailsrvr.com
Type
REG_SZ
What the values mean
  • 0 n/a - this key is a list of allowed hostnames, not a flag
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover\RedirectServers
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
<xx.0> is 16.0 for Outlook 2021, 2019, 2016 and Outlook for Microsoft 365 (per the Microsoft KB); 15.0 for Outlook 2013. Originally KB2480582.
To undo
Delete the named string value (or the whole RedirectServers key), restart Outlook.

Watch out The value NAME is the hostname to trust; the data is empty. Add one value per host.

What this costs you Must be REG_SZ, not DWORD - SmarterTools notes "Some users suggest adding this as a DWORD, but the above aligns with the Microsoft's documentation." Data must be blank. It suppresses a genuine security prompt, so only add hosts you actually own or trust. Does not affect the Autodiscover lookup order at all - purely a UX suppression.

Useful when rolling out a hosted-Exchange tenant where every new profile otherwise shows the redirect consent dialog.

Source: portal.smartertools.com, learn.microsoft.com

ZeroConfigExchange silent profile creation

Found in the field

I need Outlook to build its Exchange profile silently on first launch for a batch of machines, with no wizard and no user typing an address.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "ZeroConfigExchange" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ZeroConfigExchange"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
ZeroConfigExchange
Type
REG_DWORD
What the values mean
  • 0 default - the Add Account wizard appears on first run
  • 1 take the primary SMTP address from Active Directory, run Autodiscover and create the profile silently
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
16.0 for Outlook 2016/2019/2021/2024/365, 15.0 for Outlook 2013, 14.0 for Outlook 2010. The GPO equivalent is 'Automatically configure profile based on Active Directory Primary SMTP address'.
To undo
Delete ZeroConfigExchange (or set to 0). Existing profiles are unaffected.

What this costs you With ZeroConfigExchange set you can no longer create an additional Outlook profile for a second Exchange account at all - the wizard is bypassed. The escape hatch is a second value, ZeroConfigExchangeOnce (REG_DWORD 1) in the same key, which still auto-creates the first profile but then allows manual ones. ZeroConfigExchange always wins if both are 1, so you must remove it or set it to 0. Because it depends on the AD primary SMTP address, it is of limited use on non-domain-joined machines.

Source: woshub.com, blog.matrixpost.net, learn.microsoft.com

Force OAuth for Autodiscover and EWS

Found in the field

Mailbox was migrated to Microsoft 365 (or the profile has one on-prem and one cloud mailbox) and Outlook keeps prompting because it is sending a password instead of a token for EWS/Autodiscover.

Command
reg add "HKCU\Software\Microsoft\Exchange" /v "AlwaysUseMSOAuthForAutoDiscover" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Exchange]
"AlwaysUseMSOAuthForAutoDiscover"=dword:00000001
Key
HKCU\Software\Microsoft\Exchange
Value
AlwaysUseMSOAuthForAutoDiscover
Type
REG_DWORD
What the values mean
  • 0 default - Outlook may use legacy RPC-compatible auth for web services
  • 1 always use modern auth (OAuth) for Autodiscover and EWS
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2013 SP1 and later; the key is NOT version-numbered - it sits at HKCU\Software\Microsoft\Exchange, outside the Office 16.0 tree, so technicians looking under Office\16.0 for it will not find it. Modern auth must be enabled in the tenant for it to help.
To undo
Delete the AlwaysUseMSOAuthForAutoDiscover value, restart Outlook.

What this costs you Pointless or harmful on a pure on-premises org whose Exchange has not had OAuth/modern auth configured - Outlook will try OAuth and fail. Some migration runbooks ship this as an MSOAuthForAutodiscover.reg file applied as a post-migration step.

Source: learn.microsoft.com, woshub.com, learn.microsoft.com

MapiHttpDisabled - force RPC/HTTP

Found in the field

Outlook is slow, unresponsive or disconnecting over MAPI/HTTP and you want to force it back to RPC/HTTP (Outlook Anywhere) to prove where the fault is.

Command
reg add "HKCU\Software\Microsoft\Exchange" /v "MapiHttpDisabled" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Exchange]
"MapiHttpDisabled"=dword:00000001
Key
HKCU\Software\Microsoft\Exchange
Value
MapiHttpDisabled
Type
REG_DWORD
What the values mean
  • 0 MAPI over HTTP allowed (default; same as deleting the value)
  • 1 Outlook does not advertise the MAPI/HTTP capable flag in its Autodiscover request, so RPC/HTTP is used
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2013 SP1, Outlook 2016 and later, plus Outlook 2010 SP2 with a post-SP2 update. Like AlwaysUseMSOAuthForAutoDiscover this key is NOT under the Office 16.0 tree - it is at HKCU\Software\Microsoft\Exchange. Of historical value only against Exchange Online, which no longer offers RPC/HTTP; still useful against on-prem Exchange 2013/2016/2019.
To undo
Delete MapiHttpDisabled or set it to 0, then restart Outlook and let Autodiscover run again.

What this costs you SmarterTools: "Do not use this with accounts that utilize MAPI." Microsoft describes the setting as intended for testing only. The change does not take effect until Outlook next performs an Autodiscover query, which confuses people into thinking it did not work.

Source: blog.rmilne.ca, portal.smartertools.com

Stop AutoDiscover hitting the Microsoft 365 endpoint

Found in the field

Outlook will not stop prompting for a password on a mailbox that is not hosted in Microsoft 365, because AutoDiscover reaches the Microsoft 365 endpoint first.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "ExcludeExplicitO365Endpoint" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ExcludeExplicitO365Endpoint"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
ExcludeExplicitO365Endpoint
Type
REG_DWORD
What the values mean
  • 0 default - Outlook tries the explicit Microsoft 365 Autodiscover endpoint first (steps 4 and 11)
  • 1 skip the Microsoft 365 endpoint check entirely and carry on with normal Autodiscover
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2016 build 16.0.6741.2017 and later (Jaap Wesselius). Same key works on 2016/2019/2021/2024/365 because they are all 16.0; FrankysWeb: 'it is not necessary to adjust the version in the path (16.0), as Office 2016, 2019 and 2021 use version 16.0'. No 15.0 equivalent - the O365 endpoint check was added after Outlook 2013 shipped. Still cited as the working fix in 2025-2026 MS Q&A threads for Outlook 2021/2024.
To undo
Delete the ExcludeExplicitO365Endpoint value (or set it to 0) and restart Outlook. Several credential-prompt troubleshooting guides specifically tell you to check for this value and delete it if present, because it is also a cause of prompts in all-cloud tenants.

What this costs you If the mailbox genuinely IS in Exchange Online, Outlook loses its fastest path and falls back to DNS-based discovery; in hybrid orgs with some mailboxes in the cloud this slows or breaks profile creation for the cloud users. Also: field reports of GPO-delivered registry *preference* items silently disappearing - a sysadmin on MS Q&A wrote 'I am now finding that the registry entry is being randomly removed. I have just changed my "Create" to "Replace", so I hope that makes it stick.'

The prompt loop will not stop until the key is applied and Outlook is restarted. This is the single most useful key on this page if you buy Microsoft 365 for the Office apps but host mail somewhere else, which is a configuration Microsoft does not really acknowledge.

Source: frankysweb.de, jaapwesselius.com, portal.smartertools.com, learn.microsoft.com, learn.microsoft.com

Stop AutoDiscover probing autodiscover.domain.com over HTTPS

Found in the field

After moving mail away from on-prem Exchange, Outlook still tries the old autodiscover.domain.com host and prompts for the dead server's password.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "ExcludeHttpsAutoDiscoverDomain" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ExcludeHttpsAutoDiscoverDomain"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
ExcludeHttpsAutoDiscoverDomain
Type
REG_DWORD
What the values mean
  • 0 default - Outlook tries https://autodiscover.<domain>/autodiscover/autodiscover.xml (step 7)
  • 1 skip the autodiscover.<domain> probe
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2010/2013/2016/2019/2021/2024/365; 15.0 for Outlook 2013, 14.0 for 2010.
To undo
Delete the value or set to 0, restart Outlook.

What this costs you This is the most dangerous of the Exclude* family - it removes the normal discovery path for every non-domain-joined or off-LAN client. Jaap Wesselius, asked what breaks in hybrid: "Non domain joined clients, or domain joined clients outside the office will use the autodiscover.domain.com option, and you are going to exclude this with the ExcludeHttpsAutodiscoverDomain option. So most likely they will no longer find the internal organization". Only set it when you have another working path (SCP, SRV, or a local XML).

The previous version of this page had HHKCU in this command, with the extra H, so it silently did nothing. Worth checking your own scripts for the same typo.

Source: jaapwesselius.com, portal.smartertools.com, learn.microsoft.com

Stop AutoDiscover probing the bare domain over HTTPS

Found in the field

Outlook hangs for 10-30 seconds on startup, or throws a certificate / 'allow this website to configure settings' warning from our public web server.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover" /v "ExcludeHttpsRootDomain" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ExcludeHttpsRootDomain"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\AutoDiscover
Value
ExcludeHttpsRootDomain
Type
REG_DWORD
What the values mean
  • 0 default - Outlook tries https://<domain>/autodiscover/autodiscover.xml (step 6)
  • 1 skip the bare root-domain probe
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\AutoDiscover
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2010/2013/2016/2019/2021/2024/365. Use 15.0 in the path for Outlook 2013, 14.0 for 2010.
To undo
Delete the value or set to 0, restart Outlook.

What this costs you If your Autodiscover record legitimately lives at the root domain (some hosters publish autodiscover.xml at https://domain.tld/), excluding this step breaks discovery completely. Harmless in the normal case where the root domain is a marketing website.

Pairs with ExcludeHttpsAutoDiscoverDomain. Set both when you are chasing SSL or proxy errors during profile creation.

Source: frankysweb.de, jaapwesselius.com, portal.smartertools.com, stephenwagner.com

00036619 - Logon network security in the profile

From a Microsoft support caseUndocumented

Profile is stuck prompting for credentials and 'Logon network security' is set to something other than Anonymous Authentication - and you need to read or fix it without opening the Mail control panel on every PC.

Nothing to set here. This entry explains how the setting behaves so you can read what you find on a machine.

Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Profiles\<profile>\<provider GUID subkey>
Value
00036619
Type
REG_BINARY
What the values mean
  • 0 n/a - this is a binary MAPI property (PR_PROFILE_AUTH_PACKAGE), not a 0/1 flag
  • 1 any value other than 01 f0 00 80 means an authentication method other than Anonymous
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Microsoft documents the walk for Outlook 2013 (HKCU\Software\Microsoft\Office\15.0\Outlook\Profiles) and for 2010/2007 (HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles). The Profiles tree exists identically at 16.0, but Microsoft states that "Microsoft Outlook 2016 and some recent builds of Outlook 2013 are not affected by this issue. ... These versions have the Logon network security setting disabled or removed" - so on a pure 16.0 machine the value is usually absent and this is primarily a 2013-era/legacy-profile diagnostic.
To undo
Change 'Logon network security' back through Control Panel > Mail > the account > More Settings > Security, rather than editing the binary.

Watch out Both the profile name and the provider subkey under it vary per machine, so there is no command to paste here. Find the profile under Outlook\Profiles, then the subkey holding a 00036619 value, and set that value. 01 f0 00 80 is Anonymous Authentication.

What this costs you Microsoft: "Modifying the Outlook profile by using the 'Profiles' registry path is not supported and may cause your Outlook profile to be in an unsupported state." Treat this as read-only forensics (confirm what the profile actually has) rather than something to write. Finding the right subkey is a five-step walk: profile > 9375CFF0413111d3B88A00104B2A6676 > 0000000x (match Account Name to the SMTP address) > Service UID GUID subkey > 01023d0d GUID subkey > 00036619.

Worth knowing mainly so you can read an existing machine: if a profile is stuck prompting, this value tells you what Logon network security is actually set to without opening the Mail control panel.

Source: learn.microsoft.com, learn.microsoft.com

Remove AuthenticationService policy value

Vendor documented

Endless credential prompts with 'trying to connect...', and on the Security tab 'Logon network security' shows something other than Anonymous Authentication and is disabled.

Command
reg delete "HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security" /v "AuthenticationService" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Security]
"AuthenticationService"=-
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security
Value
AuthenticationService
Type
REG_DWORD
What the values mean
  • 9 Kerberos/NTLM Password Authentication (default)
  • 10 NTLM Password Authentication
  • 16 Kerberos Password Authentication
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
IMPORTANT CAVEAT: the Microsoft KBs that document this value (KB2975918, and the TechNet Wiki copy) only spell out x.0 = 15.0 for Outlook 2013, 14.0 for 2010 and 12.0 for 2007. The ADMX policy that writes it ('Account Settings\Exchange\Authentication with Exchange Server') also exists for Outlook 2016+, so the 16.0 path above is the same policy one version up - but do not tell a customer the 16.0 path is Microsoft-documented, because it is not. Outlook 2016+ removed the Logon network security dropdown from the UI, so a leftover value here is invisible and all the more worth checking.
To undo
Re-create the DWORD with the previous data (9, 10 or 16) if some legacy app needed it.

What this costs you This is a value to REMOVE, not to add. Setting it is what causes the symptom. If it sits under Policies it is being pushed by GPO - set 'Authentication with Exchange Server' to Not Configured instead of fighting the registry.

Source: learn.microsoft.com, learn.microsoft.com

EnableRememberPwd blocks credential caching

Vendor documented

Outlook prompts for the password but there is no 'Remember my credentials' checkbox, so it asks again every time.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Outlook\Security" /v "EnableRememberPwd" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Security]
"EnableRememberPwd"=-
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Security
Value
EnableRememberPwd
Type
REG_DWORD
What the values mean
  • 0 the 'Remember password' option is disabled - Outlook cannot cache credentials
  • 1 password caching allowed (default behaviour when the value is absent)
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
x.0 = 16.0 for Outlook 2016, Outlook for Office 365 and Outlook 2019; 15.0 = Outlook 2013; 14.0 = Outlook 2010; 12.0 = Outlook 2007.
To undo
Re-create EnableRememberPwd = 0 if your security policy requires it.

What this costs you Nothing breaks by removing it, but if the value sits in the Policies hive a Group Policy administrator has to change it - the GPO is 'Disable "Remember password" for Internet e-mail account' under User Configuration/Administrative Templates/Microsoft Outlook <version>/Security. A hardening baseline or an old security GPO is the usual source.

Setting it to 0 disables password caching; deleting it restores the default.

Source: support.microsoft.com, learn.microsoft.com

Un-grey 'Always prompt for logon credentials'

Found in the field

'Always prompt for logon credentials' is ticked and greyed out on the account's Security tab, so Outlook asks for a password every single launch.

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security" /v "PromptForCredentials" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Security]
"PromptForCredentials"=dword:00000000
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security
Value
PromptForCredentials
Type
REG_DWORD
What the values mean
  • 0 do not always prompt - Outlook tries cached credentials first
  • 1 always prompt for logon credentials (and the checkbox is locked on)
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Security
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 365 / 2019 / 2016 (16.0) per the cited source; 15.0 for Outlook 2013. This one genuinely lives in the Policies branch - that is exactly why the checkbox is greyed out in the UI, and it is extremely common on machines that were once domain-joined with a GPO and then taken out of the domain, leaving an orphaned policy value nobody can clear from the GUI.
To undo
Set back to 1 if you genuinely want the prompt, or delete the value to return control to the Outlook UI.

What this costs you If the machine is still in scope of a real GPO, the next policy refresh writes it back - fix it in the GPO, or delete the key on a machine that no longer has a domain. Clearing it will not help if the prompts actually come from Autodiscover or WAM.

Source: woshub.com

Bring back the classic account wizard

Vendor documented

The new one-box 'simplified' account wizard won't let me type a server name or pick Exchange manually, and it keeps dragging the user to a Microsoft 365 sign-in.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\setup" /v "DisableOffice365SimplifiedAccountCreation" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\setup]
"DisableOffice365SimplifiedAccountCreation"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\setup
Value
DisableOffice365SimplifiedAccountCreation
Type
REG_DWORD
What the values mean
  • 0 default - simplified (one-field) account creation wizard
  • 1 force the traditional multi-step account setup wizard
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\setup
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2016 and later (16.0). Note the key lives under ...\Outlook\setup, NOT under ...\Outlook\AutoDiscover - a very common transcription error. It has no effect on the Autodiscover lookup order itself.
To undo
Delete the value or set to 0.

What this costs you Nothing functional - it only changes the setup UI. In the newest Outlook (classic) builds Microsoft has been steadily removing manual setup paths, so confirm on the actual build in front of you rather than assuming it still restores every manual option.

Source: portal.smartertools.com, slipstick.com, learn.microsoft.com

Add-ins that disable themselves

Resiliency, Disabled Items, and the add-in that will not stay enabled.

No registry knob for the 1000ms add-in timeout

Community verified

Outlook says the add-in slowed down startup; can I just raise the time limit instead of whitelisting it?

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList" /v "TeamsAddin.FastConnect" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList]
"TeamsAddin.FastConnect"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList
Value
TeamsAddin.FastConnect
Type
REG_DWORD
What the values mean
  • 1 Exempt for boot load (LoadBehavior = 3), the 'slow to start' case.
  • 8 Exempt for shutdown, the 'caused Outlook to close slowly' case; the shutdown threshold is lower (Microsoft's own event sample shows 500 ms).
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 onward. There is no AddinStartupTimeout / LoadTimeThreshold value in Outlook; do not go looking for one, and be sceptical of any blog that invents one.
To undo
Delete the exemption value.

What this costs you Nothing to break; the point of this record is to stop a technician hunting for a threshold key that does not exist. The real diagnostics are Application event log Event ID 45 (add-in load time) and Event ID 59 (add-in disabled, with Threshold Time and Time Taken in milliseconds), plus File > Slow and Disabled COM Add-ins in the Outlook UI.

The value name is the add-in ProgID; TeamsAddin.FastConnect is shown as a worked example, so substitute your own. ProgIDs are case sensitive.

Source: learn.microsoft.com, learn.microsoft.com, rain-city.tech

Clear an add-in out of Disabled Items

From my own field workUndocumented

An add-in is greyed out in Disabled Items and setting LoadBehavior alone will not bring it back.

Command
reg delete "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Resiliency\DisabledItems" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Resiliency\DisabledItems]
Key
HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Resiliency\DisabledItems
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 and later.
To undo
Nothing to revert; Outlook rebuilds these entries the next time an add-in misbehaves.

Watch out The value names under DisabledItems are not stable - they are generated per incident, so you cannot target one by name in a script. Clearing the whole key is the practical move.

What this costs you You are clearing Outlook's record of what misbehaved, for every add-in at once, so you lose that history.

Do this together with DoNotDisableAddinList and LoadBehavior=3, otherwise Outlook disables it again on the next slow start. CrashingAddinList is the sibling key to check when the add-in crashed rather than merely loaded slowly.

Stop Outlook disabling a slow add-in

From my own field work

Outlook keeps disabling an add-in your business depends on because it loads slowly.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList" /v "SalesforceForOutlook" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList]
"SalesforceForOutlook"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList
Value
SalesforceForOutlook
Type
REG_DWORD
What the values mean
  • 1 Never disable this add-in for slow load or crashes
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 and later.
To undo
Delete the value named after the add-in.

What this costs you A genuinely broken add-in will now be allowed to keep crashing or slowing Outlook, because you have removed the safety valve.

This does NOT bring back an add-in that is already disabled. You also have to clear its entry from Resiliency\DisabledItems or CrashingAddinList, and set LoadBehavior back to 3. Doing only this key and wondering why nothing happened is the usual mistake. The value NAME is the add-in ProgID.

DoNotDisableAddinList is Outlook-centric

Community verifiedUndocumented

I copied the DoNotDisableAddinList trick to Word and Excel and it made no difference there.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Word\Resiliency\DoNotDisableAddinList" /v "TeamsAddin.FastConnect" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Resiliency\DoNotDisableAddinList]
"TeamsAddin.FastConnect"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Word\Resiliency\DoNotDisableAddinList
Value
TeamsAddin.FastConnect
Type
REG_DWORD
What the values mean
  • 0 No exemption.
  • 1 Requested exemption. Reported as effective for Outlook; contested for Word/Excel/PowerPoint.
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Resiliency\AddinList; use this instead for Word/Excel; it is the supported route and is confirmed to work per-app
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 and 15.0. Microsoft's KB header lists Word/Excel/PowerPoint 2013 and 2016 as applicable, which is why the trick gets copied across; field reports disagree on whether it has any effect outside Outlook.
To undo
Delete the value; nothing depends on it.

What this costs you Honest state of knowledge: Microsoft's KB 2758876 is written generically ('<application>') and its Applies To list includes Word and Excel, but a Microsoft Answers thread asking exactly this got a flat 'No, this registry key DoNotDisableAddinList will not work for other applications like Word/Excel', while MVP Doug Robbins argued from the KB's Applies To that it should. Treat Word/Excel as unproven and use the Policies Resiliency\AddinList route there. Also note one field report that the ClassID (rather than ProgID) form 'does not work in Word 2016 or Office 365'.

The value name is the add-in ProgID; TeamsAddin.FastConnect is shown as a worked example, so substitute your own. ProgIDs are case sensitive.

Source: learn.microsoft.com, blog.blue929.com, learn.microsoft.com

RequireAddinSig blocks unsigned add-ins

Microsoft documented

After a security baseline went on, add-ins stopped loading and users get 'The digital signature is valid but is from a publisher whom you have not yet chosen to trust'.

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\excel\security" /v "RequireAddinSig" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\excel\security]
"RequireAddinSig"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\Office\16.0\excel\security
Value
RequireAddinSig
Type
REG_DWORD
What the values mean
  • 0 Add-ins load regardless of signature (default).
  • 1 Application checks the digital signature of every add-in before loading; unsigned, or signed by a publisher not in Trusted Publishers, means the add-in is disabled and the user is notified.
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\<app>\security; app is excel, word, powerpoint, outlook, access, publisher, visio, project
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2013/2016/2019/2021/365 (16.0; 15.0 for 2013). Shipped as CIS Level 1 and DISA STIG requirement, so it is very often set by a baseline rather than deliberately.
To undo
Delete the RequireAddinSig value or set 0 (and fix the baseline, or deploy the vendor's signing certificate into the Trusted Publishers store; via Intune OMA-URI ./Device/Vendor/MSFT/RootCATrustedCertificates/TrustedPublisher/{Thumbprint}/EncodedCertificate).

What this costs you Office 2016+ reads trusted publishers from the Windows/IE Trusted Publishers store, not the old Office-specific store, and does not write to the Office store any more, so certificates that used to work silently stop working. Microsoft's own DLLs trip it (VSTOEE.DLL, FDATE.DLL, MOFL.DLL, IMCONTACT.DLL, FSTOCK.DLL, FBIBLIO.DLL and the Azure DevOps add-in are named in their KB). Expect Adobe PDFMaker 'Convert to PDF' to break too.

Source: stigviewer.com, support.microsoft.com, mobile-jon.com

Policies Resiliency\AddinList: lock an add-in on

Found in the field

I need an add-in locked on so users physically cannot untick it, and I want the setting to survive the user poking around in Options.

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList" /v "TeamsAddin.FastConnect" /t REG_SZ /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList]
"TeamsAddin.FastConnect"="1"
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList
Value
TeamsAddin.FastConnect
Type
REG_SZ
What the values mean
  • 0 Always disabled (blocked). User cannot turn it on.
  • 1 Always enabled. User cannot turn it off, and Outlook's resiliency/performance disabling will never disable it.
  • 2 Configurable by the user, and not blocked by the 'Block all unmanaged add-ins' policy.
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList (this IS the policy path; swap Outlook for Word/Excel/PowerPoint per app)
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2013 and later only (15.0 for 2013, 16.0 for 2016/2019/2021/365). GPO name: User Configuration > Administrative Templates > Microsoft Outlook 2016 > Miscellaneous > List of managed add-ins. There is no 2010 equivalent.
To undo
Delete the ProgID value (or the whole AddinList key). Note Microsoft: if you disable the policy, 'the list of managed add-ins will be deleted'.

What this costs you TYPE CONFLICT worth knowing: Microsoft's own docs and the field guides that have been field-tested (slipstick, techhit, amorales) say String/REG_SZ; Zivver's and blue929's guides say REG_DWORD. REG_SZ "1" is the safer bet because that is what the ADMX-backed policy writes. Also: a populated AddinList combined with RestrictToList=1 blocks every add-in NOT in the list; that is the usual cause of 'The add-in you have selected is disabled by your system administrator'. Writing to HKCU\Software\Policies by hand works without a domain but Intune/GPO will overwrite it.

The value name is the add-in ProgID; TeamsAddin.FastConnect is shown as a worked example, so substitute your own. ProgIDs are case sensitive.

Source: slipstick.com, techhit.com, amorales.org, learn.microsoft.com, learn.microsoft.com

AddinList also exists outside Policies

Microsoft documented

A vendor KB told me to put the add-in in Resiliency\AddinList but there's no Policies key in the path they gave, which one is right?

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\AddinList" /v "TeamsAddin.FastConnect" /t REG_SZ /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\AddinList]
"TeamsAddin.FastConnect"="1"
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\AddinList
Value
TeamsAddin.FastConnect
Type
REG_SZ
What the values mean
  • 0 Always disabled (blocked)
  • 1 Always enabled
  • 2 Configurable by the user and not blocked by 'Block all unmanaged add-ins'
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 (15.0) and later. Microsoft's own Outlook VBA reference documents the NON-Policies path for this setting while its support troubleshooter documents the Policies path for the same GPO; both appear in the wild.
To undo
Delete the ProgID value from whichever branch you wrote it to.

What this costs you This is the genuinely confusing one in this domain: two different Microsoft pages give two different branches for the same value name. The Policies branch is what the ADMX actually writes and is what takes precedence; the preference branch is what Microsoft's VBA documentation and several vendor KBs print. If one doesn't take, set both; they are not mutually exclusive and neither harms the other.

The value name is the add-in ProgID; TeamsAddin.FastConnect is shown as a worked example, so substitute your own. ProgIDs are case sensitive.

Source: learn.microsoft.com, konnectemail.com, learn.microsoft.com

CrashingAddinList: clear the crash history

Found in the fieldUndocumented

Outlook crashed once with the add-in loaded and now it refuses to load it, or the 'Outlook detected an add-in problem' prompt comes back every launch.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\CrashingAddinList" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\CrashingAddinList]
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\CrashingAddinList
What the values mean
  • 0 Key absent or empty = no crash history held against any add-in.
  • 1 A REG_BINARY entry present = Outlook recorded this add-in as having crashed it and will prompt to disable / keep it disabled.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013/2016/2019/2021/365; 15.0 for Outlook 2013, 14.0 for 2010. Paired with DisabledItems under the same Resiliency key.
To undo
Export before deleting; re-import to restore. Outlook will repopulate it on the next crash anyway.

What this costs you You are erasing evidence of a real crash. If the add-in genuinely crashes Outlook, Microsoft states resiliency cannot be suppressed for that case and the crash will simply recur. Several field guides delete and recreate the key empty so Outlook has somewhere to write; recreating it is not strictly required but is harmless.

Source: amorales.org, docs.zivver.com, dragdrop.com, optiable.com

DisabledItems blocks it until you clear it

Found in the fieldUndocumented

I added the add-in to DoNotDisableAddinList and set LoadBehavior=3 but it is STILL disabled after restarting Outlook.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DisabledItems" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\DisabledItems]
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DisabledItems
What the values mean
  • 0 No entries present = nothing hard-disabled for this app/user. This is the state you want.
  • 1 Any REG_BINARY entry present = that item is hard-disabled and Office will not load it, regardless of LoadBehavior or DoNotDisableAddinList.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013/2016/2019/2021/365 (15.0/16.0). The same key exists per app: ...\16.0\Word\Resiliency\DisabledItems, ...\16.0\Excel\Resiliency\DisabledItems. In the UI this is File > Options > Add-ins > Manage: Disabled Items.
To undo
Export the key before deleting. Re-importing restores the disable list. Otherwise, Office will simply re-add an entry the next time the add-in misbehaves.

What this costs you Clearing the key re-enables EVERY disabled item for that application and user, including ones that were disabled for good reason (and, for shim-less managed add-ins, the mscoree.dll entry). The binary blob is not human-readable so you cannot easily target one add-in in regedit.

Source: rain-city.tech, encyro.com, learn.microsoft.com, learn.microsoft.com

DoNotDisableAddinList: exempt an add-in

Microsoft documented

Outlook keeps disabling the add-in with 'this add-in caused Outlook to start slowly' and the user has to re-enable it every morning.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList" /v "TeamsAddin.FastConnect" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList]
"TeamsAddin.FastConnect"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList
Value
TeamsAddin.FastConnect
Type
REG_DWORD
What the values mean
  • 1 Boot load (LoadBehavior = 3), the reason code Outlook itself writes, and the value everyone uses as a blanket 'never disable this'.
  • 2 Demand load (LoadBehavior = 9)
  • 3 Crash
  • 4 Handling FolderSwitch event
  • 5 Handling BeforeFolderSwitch event
  • 6 Item Open
  • 7 Iteration Count
  • 8 Shutdown (the 'caused Outlook to close slowly' case)
  • 9 Crash, but not disabled because add-in is in the allow list
  • 10 0x0A, Crash, but not disabled because user selected no in the disable dialog
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList (the GPO-backed equivalent; see separate record)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 (15.0) and later; substitute 15.0 for Outlook 2013. This is what Outlook writes when the user clicks 'Always enable this add-in'. Writing it by hand is the no-GPO equivalent of that click.
To undo
Delete the ProgID value. The add-in becomes eligible for auto-disable again.

What this costs you Does NOT help when the add-in actually crashes Outlook or genuinely cannot load. Microsoft states those two cases cannot be exempted. Exempting a genuinely slow add-in means you keep the slow startup. Field reports say Office updates sometimes stop honouring it.

The value name is the add-in ProgID; TeamsAddin.FastConnect is shown as a worked example, so substitute your own. ProgIDs are case sensitive.

Source: learn.microsoft.com, learn.microsoft.com, docs.zivver.com, rain-city.tech, encyro.com

The working order: clear history, then exempt

Found in the fieldUndocumented

I've set every registry key I can find and the add-in is STILL disabled; what order do I actually do these in?

Nothing to set here. This entry explains how the setting behaves so you can read what you find on a machine.

Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency
Value
DisabledItems + CrashingAddinList (clear) then DoNotDisableAddinList (set)
Type
REG_DWORD
What the values mean
  • 0 Setting DoNotDisableAddinList while a DisabledItems entry still exists = no effect. This is the single most common reason the documented fix 'doesn't work'.
  • 1 Correct sequence: (1) re-enable in the Outlook UI or clear DisabledItems, (2) clear CrashingAddinList, (3) add ProgID=1 to DoNotDisableAddinList, (4) confirm LoadBehavior=3 in HKCU and HKLM ...\Office\Outlook\Addins\<ProgID>.
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList; belt-and-braces step 5 for environments that do have GPO/Intune
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013/2016/2019/2021/365. All four keys are per-user, so Intune/RMM scripts must run in the logged-on user's context.
To undo
Export the Resiliency key before you start; re-importing restores the original disable history and exemptions.

Watch out This entry is the order of operations, not a single value. Its 'value' column names the three keys involved rather than one value name, which is why it offers no command: do them in sequence, each from its own entry on this page.

What this costs you Deploying any of this from SYSTEM context writes to the wrong hive and silently does nothing; the field guidance is explicit that HKCU keys must run as the logged-on user. Clearing DisabledItems re-enables every disabled item for that app, not only the one you care about.

Source: rain-city.tech, rain-city.tech, encyro.com, amorales.org

Undo RestrictToList blocking every add-in

Microsoft documented

No add-ins at all are enabled and the COM Add-ins dialog says 'The add-in you have selected is disabled by your system administrator'.

Command
reg delete "HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency" /v "RestrictToList" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency]
"RestrictToList"=-
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency
Value
RestrictToList
Type
REG_DWORD
What the values mean
  • 0 Not restricted, add-ins not named in AddinList behave normally.
  • 1 Block all unmanaged add-ins. Only add-ins listed in Resiliency\AddinList with data 1 or 2 can load. If AddinList is empty, EVERY COM add-in is disabled.
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\<application>\Resiliency
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2016 and later for the 16.0 path (equivalent exists at 15.0 for Office 2013). <application> is outlook, word, excel, powerpoint etc. GPO name: Block all unmanaged add-ins.
To undo
Set RestrictToList to 1 again if you actually wanted an allow-list, having populated AddinList first.

Watch out The fix is to REMOVE this value, not to write it. Setting RestrictToList to 1 is what blocks every add-in not named in the sibling AddinList key, so the command here deletes it. If you genuinely want an allow-list, set it to 1 deliberately and populate AddinList first.

What this costs you This is the number one cause of 'all our add-ins vanished after we applied a security baseline'. CIS/STIG-style baselines and some Intune security templates set it. Deleting it on a domain-joined machine only helps until the next policy refresh; fix it at the policy source.

Source: learn.microsoft.com, learn.microsoft.com

StoreButtonInRibbonHomeTabAllowed = 0

Found in the fieldUndocumented

I need to stop users installing Office Store add-ins themselves; remove the 'Get Add-ins' / 'All Apps' button from the Outlook ribbon.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Options\Webext" /v "StoreButtonInRibbonHomeTabAllowed" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Webext]
"StoreButtonInRibbonHomeTabAllowed"=dword:00000000
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Options\Webext
Value
StoreButtonInRibbonHomeTabAllowed
Type
REG_DWORD
What the values mean
  • 0 the Get Add-ins / Store button is removed from the ribbon
  • 1 the Store button is shown (default)
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Options\Webext (later ADMX 'Hide the Office Store button' writes the same value name)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Confirmed by the author on Outlook 2016 and Outlook 2019; the value pre-dates the ADMX policy, which was added afterwards to control the same value.
To undo
Delete the value or set it to 1, then restart Outlook.

What this costs you Removes the button entirely rather than greying it out, so users report it as 'missing' rather than 'blocked'. It does not block add-ins already installed, and it does not block installation via the web (Outlook on the web / Microsoft 365 admin center) - for that you need the tenant-level store block plus the 'Block the Office Store' and 'Block web add-ins' policies. Note this is the inverse polarity of most keys on this page: here 0 is the restrictive value.

Source: urtech.ca

ActivationAlertThreshold for web add-in regex

Microsoft documented

A web (Office.js) Outlook add-in's button keeps disappearing or shows 'add-in unavailable' in the notification bar on slow machines.

Command
reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\WEF\Outlook" /v "ActivationAlertThreshold" /t REG_DWORD /d "3000" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\WEF\Outlook]
"ActivationAlertThreshold"=dword:00000bb8
Key
HKCU\SOFTWARE\Microsoft\Office\16.0\WEF\Outlook
Value
ActivationAlertThreshold
Type
REG_DWORD
What the values mean
  • 1000 The default threshold in milliseconds for Outlook to evaluate all regular expressions in a web add-in's manifest. Exceeding it makes Outlook retry later.
  • 3000 Example raised value, gives slower machines room before Outlook gives up on the add-in's activation rules.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Classic Outlook on Windows, Office 16.0. NOT honoured by Outlook on the web, new Outlook on Windows, Outlook mobile, or Outlook on Mac's new UI. Microsoft states the setting 'aren't supported' there. Only relevant to add-ins whose manifest uses ItemHasRegularExpressionMatch rules.
To undo
Delete the value to return to the 1000 ms default.

What this costs you Raising it trades startup/item-switch responsiveness for add-in availability. Irrelevant for COM add-ins; this is the web add-in (WEF) side of the house and is frequently confused with the COM resiliency 1000ms threshold, which is a different, non-configurable limit.

Milliseconds. The default behaviour is 1000.

Source: learn.microsoft.com, learn.microsoft.com

ActivationRetryLimit for web add-ins

Microsoft documented

The web add-in only comes back if the user clicks away to another email and back again.

Command
reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\WEF\Outlook" /v "ActivationRetryLimit" /t REG_DWORD /d "5" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\WEF\Outlook]
"ActivationRetryLimit"=dword:00000005
Key
HKCU\SOFTWARE\Microsoft\Office\16.0\WEF\Outlook
Value
ActivationRetryLimit
Type
REG_DWORD
What the values mean
  • 3 Default number of times Outlook re-evaluates a web add-in's regular expressions. After three failures the user must switch mail items and back to retry.
  • 5 Example raised value for flaky/slow endpoints.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Classic Outlook on Windows, Office 16.0. Mac equivalent is an ActivationRetryLimit property list in ~/Library/Preferences. Unsupported in Outlook on the web / new Outlook on Windows / mobile.
To undo
Delete the value to return to 3.

What this costs you More retries means more repeated regex evaluation per item switch, which can make item navigation feel sluggish. Telemetry Log Event ID 15 ('Add-in disabled due to string search time-out') is the confirming signal that this is your problem.

The default behaviour is 3.

Source: learn.microsoft.com, learn.microsoft.com

Clear the cached Exchange add-in manifests

Microsoft documented

A web add-in deployed from the Microsoft 365 admin centre / Exchange doesn't show up in classic Outlook on Windows, but works in Outlook on the web.

Nothing to set here. This entry explains how the setting behaves so you can read what you find on a machine.

Key
HKCU\Software\Microsoft\Office\16.0\WEF\Developer
Value
<manifest path value written by sideloading / the developer registration>
Type
REG_SZ
What the values mean
  • 0 WEF\Developer populated = a locally sideloaded add-in is registered for this user, which can mask or conflict with the Exchange-delivered copy. Clear stale entries here when a dev/test manifest is stuck.
  • 1 Exchange-delivered manifests are NOT in the registry, they are cached per mailbox on disk under %LocalAppData%\Microsoft\Office\16.0\WEF\<guid>\<base64hash>\Manifests\<ManifestID>_<ManifestVersion>.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Classic Outlook on Windows, Office 16.0 (the 16.0 folder name is used by 2016/2019/2021/365). Only applies to web/Office.js add-ins, never COM add-ins. New Outlook uses a different cache (HubAppFileCache).
To undo
Nothing to revert. Outlook rebuilds the cache on next launch.

What this costs you Deleting the WEF folder drops cached manifests for ALL web add-ins and all mailboxes in that profile; Outlook re-downloads them at next start, so the first launch is slower and an offline machine will show no web add-ins at all until it can reach Exchange. Confirm Outlook actually fetched them with Application event log Event ID 63 / 'The Exchange web service request GetAppManifests succeeded.'

There is no value to set for the repair: close Outlook and delete the on-disk manifest cache.

Source: learn.microsoft.com, codetwo.com

Add-in load behaviour

What LoadBehavior actually means, and which hive wins.

Turn a COM add-in off properly

Microsoft documented

An add-in you do not want keeps loading and slowing Outlook down.

Command
reg add "HKCU\Software\Microsoft\Office\Outlook\Addins\TeamViewerMeetingAddIn.AddIn" /v "LoadBehavior" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\TeamViewerMeetingAddIn.AddIn]
"LoadBehavior"=dword:00000000
Key
HKCU\Software\Microsoft\Office\Outlook\Addins\TeamViewerMeetingAddIn.AddIn
Value
LoadBehavior
Type
REG_DWORD
What the values mean
  • 0 Unloaded, does not load automatically. Stays 0 even after a manual load.
  • 1 Loaded, does not load automatically. Becomes 0 once it loads successfully.
  • 2 Unloaded, load at startup. This is what Office writes when a startup load FAILS.
  • 3 Loaded, load at startup. The normal healthy value. Drops to 2 if loading errors.
  • 8 Unloaded, load on demand. Becomes 9 after a successful load.
  • 9 Loaded, load on demand. Drops to 8 if loading errors.
  • 16 Loaded, load first time then on demand. Becomes 9 after the app closes.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
All versions. The Addins key is version-LESS: Software\Microsoft\Office\<app>\Addins\<ProgID>, with no 16.0 in it. Visio is the exception, at Software\Microsoft\Visio\Addins\<ProgID>. The 16.0 branch holds Resiliency, not Addins.
To undo
Set LoadBehavior to 3.

Watch out Microsoft documents that the HKEY_CURRENT_USER value overrides the HKEY_LOCAL_MACHINE default. An earlier version of this page said the reverse. To force a state for every user you must clear the per-user value, not just set the machine one.

What this costs you The add-in's features disappear. If it reinstalls or self-repairs it may set LoadBehavior back to 3.

The value is a status as well as a setting: Office rewrites it. A 3 that has become a 2 means the add-in threw an error while loading, and a 9 that has become an 8 means the same for an on-demand add-in. That is the answer to 'why did this turn itself off'. HKCU overrides HKLM, so a per-user 2 beats a machine-wide 3 and deleting the HKCU value falls back to the machine default. Common ProgIDs worth turning off: UCAddin.LyncAddin.1, TeamViewerMeetingAddIn.AddIn, OscAddin.Connect, OneNote.OutlookAddin, ColleagueImport.ColleagueImportAddin, AccessAddin.DC. For the Outlook Social Connector specifically, older guidance tells you to rename SOCIALPROVIDER.DLL and SOCIALCONNECTOR.DLL in the Office program folder. Setting OscAddin.Connect LoadBehavior to 0 does the same job without touching files Office may replace on its next repair or update - and the rename path that circulates is usually wrong anyway, since the real layout is ...\Microsoft Office\root\Office16\.

Source: learn.microsoft.com

Click-to-Run hides LoadBehavior in a virtual hive

Found in the fieldUndocumented

I set LoadBehavior=3 in HKLM\Software\Microsoft\Office\...\Addins but Office ignores it, or re-enabling through the UI writes 0 somewhere I can't find.

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Office\Word\AddIns\TeamsAddin.FastConnect" /v "LoadBehavior" /t REG_DWORD /d "3" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Office\Word\AddIns\TeamsAddin.FastConnect]
"LoadBehavior"=dword:00000003
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Office\Word\AddIns\TeamsAddin.FastConnect
Value
LoadBehavior
Type
REG_DWORD
What the values mean
  • 0 What the Office UI was observed writing into the C2R virtual hive when an add-in is re-enabled, which does not persist a working state across restarts.
  • 3 Load at startup, what you need in the virtual hive as well as the real one on C2R installs.
Branch
Preference
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Click-to-Run Office 2013/2016/2019/2021/365 only. Swap 'Word' for Outlook/Excel/PowerPoint. Omit Wow6432Node for 64-bit-registered add-ins. MSI installs of Office do not have this hive.
To undo
Delete the value you added, or run an Office Quick Repair which rebuilds the ClickToRun virtual registry.

What this costs you This is the virtualised copy Office reads for C2R; editing it by hand is unsupported and can be overwritten by an Office update or repair. Always fix the real HKLM/HKCU key too.

TeamsAddin.FastConnect stands in for your add-in ProgID in this path.

Source: add-in-express.com

LoadBehavior: what 0/1/2/3/8/9/16 mean

From a Microsoft support case

Add-in shows 'Not loaded. A runtime error occurred during the loading of the COM Add-in' and the LoadBehavior I set to 3 is back at 2 every time I restart.

Command
reg add "HKCU\Software\Microsoft\Office\Outlook\Addins\TeamsAddin.FastConnect" /v "LoadBehavior" /t REG_DWORD /d "3" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\TeamsAddin.FastConnect]
"LoadBehavior"=dword:00000003
Key
HKCU\Software\Microsoft\Office\Outlook\Addins\TeamsAddin.FastConnect
Value
LoadBehavior
Type
REG_DWORD
What the values mean
  • 0 Unloaded, don't load automatically (hard off). App never tries to load it; user or code can load manually. Stays 0 after a successful manual load.
  • 1 Loaded, don't load automatically. COM Add-ins dialog shows it loaded but it isn't loaded until loaded manually/programmatically; becomes 0 after a successful load.
  • 2 Unloaded, load at startup, i.e. 'load at startup but currently disconnected'. This is the value Office writes when a startup load FAILS. Becomes 3 on a successful load.
  • 3 Per-user 'load at startup', also wins over an HKLM 0 if an admin tried to turn the add-in off machine-wide.
  • 8 Unloaded, load on demand. Becomes 9 after a successful load.
  • 9 Loaded, load on demand (loads when the user clicks the add-in's UI). Becomes 8 if a load error occurs.
  • 16 Loaded, load first time then load on demand. Loads on the first run after registration; drops to 9 after the app closes.
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\AddinList (the only way to stop the user re-overriding it)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2013/2016/2019/2021/365 and earlier. IMPORTANT: the per-add-in Addins key is version-LESS for most apps. Microsoft documents it as Root\Software\Microsoft\Office\<application name>\Addins\<add-in ID> (Visio is Root\Software\Microsoft\Visio\Addins\<add-in ID>). Do not look for it under 16.0; the 16.0 branch holds Resiliency, not Addins.
To undo
Set LoadBehavior back to 3 (or to whatever the installer's value was; some vendors legitimately ship 9 or 16 for on-demand add-ins).

What this costs you Nothing breaks, but a loop of 'set 3, restart, it's 2 again' is the single most common wasted hour on these tickets. Common real causes from the same Microsoft support write-up: missing dependency DLL, missing .NET/PIA, antivirus blocking, a stray winword.exe.config / outlook.exe.config, or a conflicting add-in.

TeamsAddin.FastConnect stands in for your add-in ProgID in this path.

Source: learn.microsoft.com, learn.microsoft.com, optiable.com, forums.slipstick.com

Turn off the Send To Bluetooth add-in across Office

Found in the fieldUndocumented

Templates with macros throw errors about the .dot file or building blocks, and the Send To Bluetooth add-in is in the list.

Command
reg add "HKLM\Software\Microsoft\Office\Word\Addins\btmoffice.Connect" /v "LoadBehavior" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Office\Word\Addins\btmoffice.Connect]
"LoadBehavior"=dword:00000000
Key
HKLM\Software\Microsoft\Office\Word\Addins\btmoffice.Connect
Value
LoadBehavior
Type
REG_DWORD
What the values mean
  • 0 Off
  • 3 On
Branch
Preference
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Office 2013 and later, where a Bluetooth stack installed the add-in. The Addins key carries no version number.
To undo
Set LoadBehavior to 3.

Watch out There is no 16.0 in this path. Add-in registration is version-less; only Resiliency lives under 16.0.

What this costs you You lose Send To Bluetooth from the Office share menus, which almost nobody uses.

Repeat under the Excel, PowerPoint and Outlook paths - it registers into each app separately, so turning it off in Word alone does not stop the errors. On 64-bit Windows with 32-bit Office also check the Wow6432Node copy of the HKLM path.

Source: learn.microsoft.com

Manifest value and the |vstolocal suffix

Microsoft documented

A VSTO add-in installed by MSI doesn't load, or loads an old version, and the add-in's Location in Options points at a ClickOnce cache path.

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\Vendor.OutlookAddin" /v "Manifest" /t REG_SZ /d "file:///C:\Program Files\Vendor\Addin.vsto|vstolocal" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\Vendor.OutlookAddin]
"Manifest"="file:///C:\\Program Files\\Vendor\\Addin.vsto|vstolocal"
Key
HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\Vendor.OutlookAddin
Value
Manifest
Type
REG_SZ
What the values mean
  • 0 Path without |vstolocal, the solution is loaded from the ClickOnce cache, which is the classic cause of 'my update didn't take' and of per-user-only availability.
  • 1 Path with the file:/// prefix and |vstolocal suffix, solution loads from the install folder, which is what a Windows Installer deployment requires.
Branch
Preference
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
All VSTO add-ins, Office 2013 onward. Mirror the key under HKLM\Software\WOW6432Node\Microsoft\... as well when targeting all users on 64-bit Windows, because the user may run either 32-bit or 64-bit Office. Per-user (HKCU) installs don't need WOW6432Node because HKCU\Software is shared.
To undo
Restore the installer's original Manifest string, or repair/reinstall the add-in.

What this costs you Only ClickOnce deployments register under HKCU; a ClickOnce-deployed add-in can never be registered for all users. Hand-editing Manifest to a path that doesn't exist makes the add-in silently absent. The three sibling values matter too: Description (REG_SZ) is what shows in the Add-ins pane, FriendlyName (REG_SZ) is what shows in the COM Add-ins dialog; a missing FriendlyName is why an add-in sometimes appears as a blank or raw-ID row.

Vendor.OutlookAddin stands in for the add-in ID; substitute the one the installer registered.

Source: learn.microsoft.com

VSTO_SUPPRESSDISPLAYALERTS=0 to see the error

Vendor documentedUndocumented

The add-in just says 'Not loaded. A runtime error occurred during the loading of the COM Add-in' and I need the real error.

Command
reg add "HKCU\Environment" /v "VSTO_SUPPRESSDISPLAYALERTS" /t REG_SZ /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Environment]
"VSTO_SUPPRESSDISPLAYALERTS"="0"
Key
HKCU\Environment
Value
VSTO_SUPPRESSDISPLAYALERTS
Type
REG_SZ
What the values mean
  • 0 Show the full VSTO/Office load error in a message box when the add-in is loaded or re-enabled.
  • 1 Suppress the messages (also achieved by deleting the variable), the normal production state.
Branch
Preference
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
All VSTO add-ins on Office 2013 onward. Diagnostic only; set it, reproduce, read the dialog, remove it.
To undo
Delete the value (or set it to 1) and restart Outlook.

What this costs you Be precise about what this is: every source documents it as a Windows ENVIRONMENT VARIABLE set via System Properties > Environment Variables, not as an Office registry setting. HKCU\Environment is simply where Windows stores per-user environment variables, which is what makes it settable remotely with reg add, but no source states that path explicitly, so treat the path as the Windows mechanism rather than a cited Office key. Office must be fully closed and relaunched (the process needs a fresh environment block) or you will see nothing. Leaving it at 0 in production throws error dialogs at users.

Source: oneplacesolutions.com, learn.microsoft.com

Sign-in, identity and activation

Wrong account, stale token, activation loop.

Autoorgidgetkey: silent activation with federated creds

Vendor documented

"Sign in to set up Office" appears at first launch even though the user is already signed into Windows with their work account - or, the opposite, Office silently grabs the domain account you did not want it to use.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common" /v "Autoorgidgetkey" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common]
"Autoorgidgetkey"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common
Value
Autoorgidgetkey
Type
REG_DWORD
What the values mean
  • 0 Office does not auto-activate from the signed-in federated/organisation credentials - the user is prompted
  • 1 Office activates silently on first launch using the already-signed-in organisation credentials
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common (value name autoorgidgetkey - ADMX policy "Automatically activate Office with federated organization credentials")
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Reboot
Applies to
16.0. Microsoft names the preference-branch form specifically in the FSLogix section of its shared-computer-activation troubleshooter, which is where it most often matters.
To undo
Delete the value from both branches. Setting it to 0 is not the same as deleting it where a policy is present.

What this costs you Be honest about the reverse case: setting the policy copy to 0 to STOP automatic sign-in is widely reported not to work. One admin on Microsoft Q&A: "that registry key did not work when I set it to apply to the current user with a group policy setting. When opening any of the Office 365 programs on an account that had never been signed in before on that computer, Office still automatically signed in ... after about 2 seconds". A second responder got it working for 2 of 3 users. If you need to hard-stop the wrong account, SignInOptions is the reliable lever, not this. Note also the policy branch wins over the preference branch, so a GPO of 0 will defeat a local 1.

Source: learn.microsoft.com, learn.microsoft.com, admx.help

Delete Common\CloudPolicy to force a policy check-in

Community verifiedUndocumented

You changed a Cloud Policy / Intune Office policy and the client has not picked it up, or an old tenant's cloud policy is still clamping sign-in on this profile.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\CloudPolicy" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\CloudPolicy]
Key
HKCU\Software\Microsoft\Office\16.0\Common\CloudPolicy
What the values mean
  • present Click-to-Run records the last fetch time and payload hash here and will not re-fetch until the fetch interval (90 minutes by default) elapses
  • absent The next Office app launch triggers an immediate Cloud Policy check-in
Branch
Preference
Policy equivalent: The policies themselves land in HKCU\Software\Policies\Microsoft\Cloud\Office\16.0 - a different branch from the GPO/ADMX branch HKCU\Software\Policies\Microsoft\Office\16.0
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Microsoft 365 Apps 16.0 with Cloud Policy service (OCPS). Does not exist on perpetual/volume Office or Office 2013.
To undo
Nothing to revert - Office recreates CloudPolicy on the next check-in. Deleted policy payloads come back only if the user still signs into a tenant that assigns them.

What this costs you This is the closest thing to gpupdate /force for Office cloud policy; there is no supported command. It only forces a re-fetch - it does not remove policies already applied. If your goal is to strip an old tenant's settings (for example a SignInOptions=2 the user can no longer satisfy) you must delete HKCU\Software\Policies\Microsoft\Cloud\Office\16.0 as well, and accept that every other cloud-pushed Office setting on that profile goes with it.

Source: github.com, techcommunity.microsoft.com, learn.microsoft.com

Delete HKCU Common\Licensing to reset the client licence

From a Microsoft support case

Office is licensed in the tenant but the client still shows the old licence/SKU, or you need to switch a device from one licence mode to another.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\Licensing" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing]
Key
HKCU\Software\Microsoft\Office\16.0\Common\Licensing
What the values mean
  • present Office reuses the cached per-user licensing state
  • absent Office re-evaluates licensing from the token store and the Office Licensing Service at next launch
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0, Microsoft 365 Apps and subscription Office 2016+. Note the separate App-V location HKLM\SOFTWARE\Microsoft\Office\16.0\Common\Licensing, which is where token-roaming settings live under App-V - do not confuse the two.
To undo
No undo. Office rebuilds the key once it re-licenses. Export first.

What this costs you This is step 6 of Microsoft's own activation reset and is only meaningful as part of the full sequence: remove the token files from %localappdata%\Microsoft\Office\Licenses (vNext, 1909+) and %localappdata%\Microsoft\Office\16.0\Licensing (shared computer activation), clear legacy keys with ospp.vbs /unpkey, THEN delete this key, then clear Identity. Deleting it alone usually changes nothing. Office drops to reduced-functionality mode until it re-licenses, so do not do it to a user who has no internet connectivity.

Source: learn.microsoft.com, support.bemopro.com

DeviceBasedLicensing on ClickToRun

Vendor documented

A shared/kiosk/lab PC needs licensed Office without anyone signing in, but Office keeps demanding a user account.

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "O365ProPlusRetail.DeviceBasedLicensing" /t REG_SZ /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"O365ProPlusRetail.DeviceBasedLicensing"="1"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
O365ProPlusRetail.DeviceBasedLicensing
Type
REG_SZ
What the values mean
  • 0 User-based licensing - Office is licensed by the signed-in user's account
  • 1 Device-based licensing - the device itself is licensed and anyone who logs on gets a licensed Office
Branch
Preference
Policy equivalent: Computer Configuration policy "Use a device-based license for Microsoft 365 Apps for enterprise"
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Reboot
Applies to
Microsoft 365 Apps for enterprise Version 1909 or later. The value name is product-prefixed - it is O365ProPlusRetail.DeviceBasedLicensing, not a bare DeviceBasedLicensing, and the prefix must match the installed Product Release ID. It is a REG_SZ.
To undo
Set to 0 or delete the value, reboot, and reset the activation state.

What this costs you Mutually exclusive with shared computer activation: Microsoft's SCA troubleshooter tells you to "Make sure Device-based licensing and robotic process automation (RPA) are disabled" before chasing SCA faults, and the two fighting is a real-world cause of activation failure on session hosts. It also requires the tenant to hold the device-based licence SKU and the device to be Entra-joined and in the right group - the registry value alone licenses nothing.

Source: uga.teamdynamix.com, learn.microsoft.com, learn.microsoft.com

DisableAADWAM (blank/looping sign-in window)

Found in the fieldUndocumented

Repeated password prompts in Outlook on a federated / ADFS tenant, or on an RDS/Citrix session host, where the WAM broker can't get a token.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Identity" /v "DisableAADWAM" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity]
"DisableAADWAM"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity
Value
DisableAADWAM
Type
REG_DWORD
What the values mean
  • 0 Default - Office uses the Entra ID (Azure AD) WAM plugin for sign-in
  • 1 disable the Entra WAM plugin; Office authenticates via ADAL instead
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 16.0 builds 16.0.7967 and later (the WAM switchover) on Windows 10 1703+. Still being passed around in 2026 for Outlook 2019 / 2021 LTSC / Office 2024 LTSC clients that cannot reach Exchange Online, usually alongside DisableADALatopWAMOverride=1 and EnableAdal=1.
To undo
Delete the value, restart the apps, and verify the Microsoft Entra / MSA WAM plugins are actually present on the device (a missing plugin, not this key, is the real cause in many cases).

What this costs you Same unsupported-configuration caveat as DisableADALatopWAMOverride, plus: the user's Office sign-in stops participating in device SSO, so they will authenticate interactively on every new session. The original reporter of this workaround later noted that an Office update fixed the underlying bug for them - so check the client is current before reaching for the registry.

Source: techcommunity.microsoft.com, woshub.com, mismosupport.freshdesk.com, learn.microsoft.com, blog.jitdor.com, borncity.com

DisableADALatopWAMOverride (WAM sign-in loop)

Found in the fieldUndocumented

Office/Outlook sign-in loops: the credential window flashes and vanishes, or it prompts endlessly after a password reset, on an Entra-joined or hybrid PC.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Identity" /v "DisableADALatopWAMOverride" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity]
"DisableADALatopWAMOverride"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity
Value
DisableADALatopWAMOverride
Type
REG_DWORD
What the values mean
  • 0 Default - Office uses Web Account Manager (WAM) for sign-in on Windows 10 1703+ (Office build 16.0.7967 and later)
  • 1 Suppress WAM and fall back to the legacy ADAL sign-in stack
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 16.0 build 16.0.7967 and later on Windows 10 build 15063.138 and later - below that build WAM is not used and the key is a no-op. 15.0 equivalent is the same value under HKCU\Software\Microsoft\Office\15.0\Common\Identity for Outlook 2013.
To undo
Delete the value and restart the Office apps. Also re-run the signoutofwamaccounts.ps1 script or clear %LOCALAPPDATA%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts if the broker state is what was broken.

What this costs you Microsoft explicitly does not support this as a fix and the warning is now sharper than it used to be: "To support compliance with the Digital Markets Act (DMA) in the European Economic Area (EEA), the manner in which users sign in to apps on Windows is managed through enforcement within WAM. Disabling WAM authentication puts the Office client into a legacy state and a Microsoft unsupported configuration." You also lose device-based Conditional Access signals, Windows Hello sign-in, and you will be asked for MFA less often - which is a security regression, not a win. Use it to get a user working today, then remove it once the underlying cause (broken AAD BrokerPlugin, stale PRT, proxy blocking) is fixed.

Source: techcommunity.microsoft.com, woshub.com, mismosupport.freshdesk.com, urtech.ca, learn.microsoft.com, blogs.it.ox.ac.uk, learn.microsoft.com

EnableADAL=0 (per-user, unsupported fallback)

Found in the field

Outlook shows an endless modern-auth sign-in window, a blank sign-in page, or 'your account requires attention' and never completes.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Identity" /v "EnableADAL" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity]
"EnableADAL"=dword:00000000
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity
Value
EnableADAL
Type
REG_DWORD
What the values mean
  • 0 Modern authentication off for this user's Office apps - legacy auth path
  • 1 Modern authentication on (the default for 16.0)
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 16.0 (2016/2019/2021/2024/365); the 15.0 counterpart for Outlook 2013 is HKCU\SOFTWARE\Microsoft\Office\15.0\Common\Identity with EnableADAL plus a 'Version' DWORD. Basic auth to Exchange Online was retired, so on an Exchange Online mailbox setting 0 today will simply stop Outlook connecting - the useful direction in 2026 is finding a stale 0 left behind by an old fix and setting it back to 1.
To undo
Delete the value or set it to 1, restart the Office apps, and remove any DisableAADWAM / DisableADALatopWAMOverride values set alongside it.

What this costs you Read this before using it. Basic/legacy authentication to Exchange Online has been retired, so EnableADAL=0 will usually make things worse, not better, on a Microsoft 365 mailbox - it is only ever viable against on-premises Exchange. It breaks MFA, Conditional Access, certificate-based auth and smart-card sign-in, and for subscription Office it will break activation outright. Microsoft states plainly that disabling ADAL is not supported as a fix. Include it on a reference page as a thing to recognise and remove, not as a recommendation.

Source: techcommunity.microsoft.com, woshub.com, urtech.ca, learn.microsoft.com, learn.microsoft.com

EnableADAL=1 machine-wide for RDS/VDI activation

Vendor documented

Shared computer activation on RDS/VDI fails or users are prompted to activate at every logon, and modern auth looks disabled machine-wide.

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\16.0\Common\Identity" /v "EnableADAL" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\Identity]
"EnableADAL"=dword:00000001
Key
HKLM\SOFTWARE\Microsoft\Office\16.0\Common\Identity
Value
EnableADAL
Type
REG_DWORD
What the values mean
  • 0 Modern authentication (ADAL) disabled for Office on this machine - a common cause of SCA failure on session hosts
  • 1 Modern authentication enabled (required for shared computer activation to obtain a licensing token)
Branch
Preference
Scope
All users on the machine, needs an elevated prompt
To take effect
Reboot
Applies to
16.0. For Office 2013 modern auth is off by default and the 15.0 equivalent must be enabled explicitly - that is a different and separately documented exercise.
To undo
Delete the value to return to the product default (ADAL on for 16.0).

What this costs you Enabling it is the safe direction. The dangerous direction is the HKCU EnableADAL=0 that circulates on forums - see the separate record. Note the HKLM value is machine-wide and will be read for every session on an RDS host.

Source: learn.microsoft.com

FSLogix IncludeOfficeActivation=0

Vendor documented

On FSLogix with SSO, Office activation breaks or users are re-prompted because the activation data is being captured into the Office container.

Command
reg add "HKLM\SOFTWARE\Policies\FSLogix\ODFC" /v "IncludeOfficeActivation" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\FSLogix\ODFC]
"IncludeOfficeActivation"=dword:00000000
Key
HKLM\SOFTWARE\Policies\FSLogix\ODFC
Value
IncludeOfficeActivation
Type
REG_DWORD
What the values mean
  • 0 Office activation data is NOT included in the FSLogix Office container - required when using SSO
  • 1 Activation data is redirected into the Office container
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\FSLogix\ODFC (FSLogix's own policy location - note this path carries no Office 16.0 segment)
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Reboot
Applies to
FSLogix Office Container (ODFC) on any host running Microsoft 365 Apps 16.0. Version-independent of Office itself.
To undo
Set to 1 or delete the value and reboot.

What this costs you This is the counterintuitive one: with SSO configured you want activation data OUT of the container, because the token should follow the identity rather than the container. If you also configured SCLCacheOverride token roaming you now have two mechanisms competing for the same token - pick one. Microsoft's broader FSLogix guidance is that when the Office container is combined with another profile solution, the Licensing folder must be excluded from that other solution's handling.

Source: learn.microsoft.com

Clear cached identities under Identity\Identities

Vendor documented

"Sorry, another account from your organization is already signed in on this computer", or Office keeps re-offering a stale account at the activation prompt.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\Identity\Identities" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Identities]
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity\Identities
What the values mean
  • present Office has one subkey per account it has ever seen; a stale one is what gets re-offered
  • absent Office rebuilds Identities from scratch at next launch and presents a clean sign-in prompt
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for Office 2013 onward in path terms, but note Office 2013 lives under 15.0 and only supports one Microsoft 365 sign-in per tenant per session - which is why 15.0 hits the 'already signed in' error far more often.
To undo
There is no undo - the user signs in again and Office recreates the subkeys. Export the Identities key before deleting if you want a rollback.

What this costs you Everything identity-shaped resets for that profile: roaming settings, recent-documents cloud list, connected services, and for subscription Office the activation token association. The user must sign in again. Delete only the offending GUID subkey first if you want to keep the good account working.

Source: learn.microsoft.com, urtech.ca, dennisspan.com, support.bemopro.com

Delete stale cached Office identities

Found in the fieldUndocumented

After a tenant-to-tenant move Outlook keeps signing in to the OLD tenant, returns the wrong Tenant ID, or says 'another account from your organization is already signed in on this computer'.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\Identity\Identities" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Identities]
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity\Identities
What the values mean
  • 0 n/a - this is a cache key to delete, not a flag
  • 1 n/a
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Reboot
Applies to
Office 16.0 (2016/2019/2021/2024/365); same structure at 15.0 for Office 2013. Subkeys are named like xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx_ADAL. With Shared Computer Activation also clear the Identity key under HKEY_USERS\<user SID>\SOFTWARE\Microsoft\Office\16.0\Common.
To undo
Restore the exported key, or simply sign back in - Office rebuilds Identities on next sign-in.

What this costs you The user is signed out of every Office app and will have to re-authenticate (and re-activate on SCA hosts). Modifying Outlook's Profiles tree directly is unsupported by Microsoft; the Identity cache is safer but still back it up first. Registry-only clearing often is not enough - the same field threads say you also have to move or delete %LocalAppData%\Microsoft\OneAuth and %LocalAppData%\Microsoft\IdentityCache, and clear MicrosoftOffice*Data entries in Windows Credential Manager.

You can remove the whole Identities key, or just the <GUID>_ADAL subkey belonging to the tenant being left.

Source: chicagotech.net, woshub.com, learn.microsoft.com

Delete Common\Identity to reset the account

From a Microsoft support case

After a tenant-to-tenant migration or repurposing a PC, Office/Outlook/OneDrive keeps resolving sign-in to the old tenant and shows "Product Deactivated".

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\Identity" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity]
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity
What the values mean
  • present Office reuses the cached account, tenant hint and signed-out state
  • absent Office starts completely unauthenticated and asks who you are at next launch
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 (Office 2016 through Microsoft 365 Apps). 15.0 for Office 2013, 14.0 for Office 2010 - same relative path.
To undo
No undo; export the subtree first. User signs in again and Office rebuilds it.

What this costs you Broader than deleting just Identities: it also removes SignedOutADUser, EnableADAL/WAM overrides and any NoDomainUser you set, so previously-applied identity fixes vanish. On a shared-computer-activation box you must ALSO remove the Identity key under HKEY_USERS\<SID>\Software\Microsoft\Office\16.0\Common, or the SCA token keeps the old account alive. Pair it with deleting %localappdata%\Microsoft\IdentityCache and clearing Office entries from Windows Credential Manager, otherwise the old tenant comes straight back.

Source: learn.microsoft.com, learn.microsoft.com, techcommunity.microsoft.com

Clear Identity\Profiles GUID keys

Found in the fieldUndocumented

Activation still fails after clearing Identities - Office seems to remember a profile that no longer exists.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\Identity\Profiles" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Profiles]
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity\Profiles
What the values mean
  • present Cached per-identity profile data (display name, tenant, licence hints) is reused
  • absent Office rebuilds profile data after the next successful sign-in
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0; the sibling of Identities, present on Office 2016 onward. Not reliably present on 15.0.
To undo
No undo; export first. Recreated on next sign-in.

What this costs you Low risk on its own, but pointless unless you also clear Identities - the two are paired. Expect a sign-in prompt and loss of the cached display name/photo.

Source: dennisspan.com

NoDomainUser to force credential re-prompt

Vendor documented

Activation keeps failing on a domain-joined or hybrid-joined PC even after clearing Identities - Office pre-fills the domain account and then errors.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Identity" /v "NoDomainUser" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity]
"NoDomainUser"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity
Value
NoDomainUser
Type
REG_DWORD
What the values mean
  • 0 Default behaviour - Office uses the signed-in domain/Entra identity when it can
  • 1 Office stops relying on the domain user context for activation and prompts/stores credentials in Credential Manager instead
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Reboot
Applies to
16.0 - Microsoft's shared-computer-activation troubleshooter names it for Office 2016 onward. No documented 15.0 equivalent.
To undo
Delete the NoDomainUser value (or set to 0) and reboot. Clear the Office entries from Credential Manager afterwards.

What this costs you You lose silent SSO activation for that user: expect an interactive credential prompt. Microsoft documents it as a second-line step only after deleting Identities, and gives no explanation of the mechanism - treat it as a targeted workaround, not a standard build setting. Do not deploy it fleet-wide; it will generate password prompts everywhere.

Source: learn.microsoft.com, learn.microsoft.com

Delete the Common\OEM key (repeat activation prompt)

Vendor documented

A correctly volume-licensed Office Standard / Pro Plus keeps asking to activate or to sign in on a new PC that shipped with a preinstalled consumer Office.

Command
reg delete "HKLM\SOFTWARE\Microsoft\Office\16.0\Common\OEM" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\OEM]
Key
HKLM\SOFTWARE\Microsoft\Office\16.0\Common\OEM
What the values mean
  • present Office sees the OEM/preinstall marker left by the machine's bundled Office and keeps steering the user toward a consumer activation/sign-in path
  • absent Office uses its volume licence and stops prompting
Branch
Preference
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Microsoft lists Office 2016, 2019, 2021 and 2024. Delete it in BOTH places on 64-bit Windows: HKLM\SOFTWARE\Microsoft\Office\16.0\Common\OEM and HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\16.0\Common\OEM.
To undo
Re-import the .reg file you exported before deleting. There is no other way back.

What this costs you Only applies to volume-licensed editions (Office Standard / Professional Plus). If the install is actually a retail or Microsoft 365 install, deleting this does nothing and you are chasing the wrong fault - check File > Account for the real SKU first. Export the key before deleting, as Microsoft itself instructs.

Source: support.microsoft.com

RestrictTeamsSignInToAccountsFromTenantList

Found in the field

You need to stop staff signing the Teams/Office client into a second (personal or consultancy) tenant on a company device.

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Teams" /v "RestrictTeamsSignInToAccountsFromTenantList" /t REG_SZ /d "a662313f-14fc-43a2-9a7a-d2e27f4f3478" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Teams]
"RestrictTeamsSignInToAccountsFromTenantList"="a662313f-14fc-43a2-9a7a-d2e27f4f3478"
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Teams
Value
RestrictTeamsSignInToAccountsFromTenantList
Type
REG_SZ
What the values mean
  • unset The client may sign into any tenant the user has an account in
  • one or more tenant IDs Sign-in is allowed only to the listed tenants
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Teams (ADMX branch) and HKCU\Software\Policies\Microsoft\Cloud\Office\16.0\Teams (Cloud Policy branch)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office/Teams 16.0 clients. The client checks three locations in order - the Cloud Policy branch, the ADMX policy branch, and the plain preference branch HKCU\Software\Microsoft\Office\16.0\Teams, which is the one to use on a machine with no GPO.
To undo
Delete the value from whichever of the three locations you set it in, and restart the client.

What this costs you This is a client-side guard rail, not a security control - it governs the desktop client only and does nothing about browser access, so do not sell it as tenant restriction. For genuine enforcement you need Entra Tenant Restrictions v2 or proxy-level Restrict-Access-To-Tenants headers. Get the GUID wrong and nobody can sign in at all. It is also a per-user HKCU value on a non-managed machine, so a determined user can simply delete it.

The data is your own tenant GUID; several can be given separated by commas. The GUID shown is an example.

Source: office365itpros.com, learn.microsoft.com

SCLCacheOverride: roam the licensing token

Microsoft documented

Non-persistent VDI or roaming users are asked to activate Office at every logon because the licensing token is tied to the local machine.

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "SCLCacheOverride" /t REG_SZ /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"SCLCacheOverride"="1"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
SCLCacheOverride
Type
REG_SZ
What the values mean
  • 0 Default - the licensing token is written to %localappdata%\Microsoft\Office\16.0\Licensing on that machine only
  • 1 Roam the token to the folder named in the companion value SCLCacheOverrideDirectory
Branch
Preference
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\office\16.0\common\licensing (ADMX "Specify the location to save the licensing token used by shared computer activation", Computer Configuration > Microsoft Office 2016 (Machine) > Licensing Settings)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Reboot
Applies to
Version 1704 of Microsoft 365 Apps and later. Under App-V the location is different: HKLM\SOFTWARE\Microsoft\Office\16.0\Common\Licensing.
To undo
Delete both SCLCacheOverride and SCLCacheOverrideDirectory and reboot; Office reverts to the local %localappdata%\Microsoft\Office\16.0\Licensing folder. Existing tokens in the override folder can be deleted.

What this costs you Requires the companion REG_SZ SCLCacheOverrideDirectory holding a path unique to each user that Office can write to. Get that wrong - a shared path used by two users, or a path Office cannot write - and nobody activates. A network share introduces latency on every Office launch, which users experience as slow-opening apps. If you use FSLogix, roaming the token this way can conflict with FSLogix handling the Licensing folder; pick one mechanism.

Source: learn.microsoft.com, guptanishith.com, learn.microsoft.com

SharedComputerLicensing on ClickToRun

Microsoft documented

On an RDS/terminal server or shared PC, each user who signs in burns an activation, or Office shows "The products we found in your account cannot be used to activate Office in shared computer scenarios".

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "SharedComputerLicensing" /t REG_SZ /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"SharedComputerLicensing"="1"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
SharedComputerLicensing
Type
REG_SZ
What the values mean
  • 0 Normal per-user product-key activation, counts against the user's 5-device limit
  • 1 Shared computer activation - each signed-in user gets a 30-day licensing token in their own profile and it does not count against the device limit
Branch
Preference
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\office\16.0\common\licensing (ADMX "Use shared computer activation", Computer Configuration > Microsoft Office 2016 (Machine) > Licensing Settings). Not supported for Microsoft 365 Apps for business - registry or ODT only there.
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Reboot
Applies to
Click-to-Run 16.0 (Microsoft 365 Apps for enterprise and for business, plus subscription Project/Visio). It is a REG_SZ, not a DWORD - several field writeups call it a DWORD and a DWORD is the single most common reason a tech's 'correct' setting does nothing. Not applicable to volume-licensed Office 2019/2021/2024 LTSC or Office for Mac.
To undo
Set to 0 or delete the value, reboot, and reset the activation state so users pick up a normal product-key licence.

What this costs you Two traps worth documenting. First: a user who already activated normally must have their activation reset before SCA will work - "If a user already activated the Microsoft 365 Apps before shared computer activation was enabled, you have to reset the activation to allow shared computer activation to work." Second: the registry side can be perfect and activation still fails with 0x80004005 if the tenant-side service plan is off - one engineer found "the 'Office Shared Computer Activation' feature in the Microsoft 365 Business Premium license's Group-based Enabled Services was disabled" and enabling it fixed it immediately. Also: Business Standard does not include SCA at all; only Business Premium among the business plans does.

Source: learn.microsoft.com, alven.tech, guptanishith.com

Allow only work accounts to sign into Office

Found in the fieldUndocumented

Users keep signing into Office with their personal Microsoft account instead of the work account, or you need to stop Office sign-in entirely on a shared/standalone PC.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\SignIn" /v "SignInOptions" /t REG_DWORD /d "2" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SignIn]
"SignInOptions"=dword:00000002
Key
HKCU\Software\Microsoft\Office\16.0\Common\SignIn
Value
SignInOptions
Type
REG_DWORD
What the values mean
  • 0 default behaviour (sign-in offered) - not independently verified here, so do not quote other values as fact
  • 1 Microsoft Account only - blocks the work/school account
  • 2 Org ID only - blocks personal Microsoft accounts (the usual business setting)
  • 3 the value used in the cited field fix - users are not offered Office sign-in (neither Microsoft account nor organization ID)
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\SignIn
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 16.0 (2016/2019/2021/2024/365). Reported working against Outlook 2021 and 2024 in 2026, in a shop with no Microsoft 365 accounts at all - it was applied together with ExcludeExplicitO365Endpoint=1, ExcludeHttpsRootDomain=1, ExcludeLastKnownGoodURL=1, EnableADAL=0 and UseOnlineContent=0 under HKCU\Software\Microsoft\Office\16.0\Common\Internet.
To undo
Set to 0 or delete the SignInOptions value. If you set it in the Policies branch, delete it there too - the policy branch overrides the preference branch and techs regularly 'fix' the wrong one.

What this costs you Value 3 is heavy-handed: it kills roaming settings, OneDrive/SharePoint 'Open from' locations, and in subscription Office it will stop activation sign-in, producing 'Product Deactivated'. On volume-licensed Office 2019/2021 value 3 is safe because licensing does not depend on sign-in. The ADMX text is explicit that this policy does not control licensing - so it does not help and does not hurt MAK/KMS activation.

This is the fix when a user has signed in with their own Outlook.com address and Office is reporting the wrong licence or no licence.

Source: forums.anandtech.com, gpedit.tplant.com.au, learn.microsoft.com, learn.microsoft.com

Delete SignedOutADUser to restore auto sign-in

Vendor documentedUndocumented

A user signed out of Office once on a domain-joined PC and now never gets signed in automatically again - they have to sign in manually every time.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Identity" /v "SignedOutADUser" /t REG_SZ /d "delete the value" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity]
"SignedOutADUser"="delete the value"
Key
HKCU\Software\Microsoft\Office\16.0\Common\Identity
Value
SignedOutADUser
Type
REG_SZ
What the values mean
  • present Office remembers that this AD user deliberately signed out and refuses to auto-sign-in with their domain credentials
  • absent Office resumes automatic sign-in using the Windows/AD credentials at next launch
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 = Office 2016+, 15.0 = Office 2013, 14.0 = Office 2010 - Microsoft's article gives the version placeholder explicitly. Set by Office itself; it never exists on a machine where nobody has signed out.
To undo
Sign out of Office again from File > Account and the value comes back.

What this costs you Nothing breaks, but it is a user-intent flag - if the user signed out on purpose (shared desk, wrong account) deleting it will silently sign them back in. The exact value type is not stated by Microsoft; the instruction is to delete whatever is there, so delete rather than overwrite.

Source: learn.microsoft.com, learn.microsoft.com

Orphaned Cloud Policy SignInOptions branch

Found in the fieldUndocumented

A personal Microsoft account still cannot sign into Office after the work account was disconnected and the machine left the tenant - Office insists on a business account that no longer exists.

Command
reg add "HKCU\Software\Policies\Microsoft\Cloud\Office\16.0\Common\SignIn" /v "SignInOptions" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Cloud\Office\16.0\Common\SignIn]
"SignInOptions"=dword:00000000
Key
HKCU\Software\Policies\Microsoft\Cloud\Office\16.0\Common\SignIn
Value
SignInOptions
Type
REG_DWORD
What the values mean
  • 0 Anything goes - personal Microsoft account or work account
  • 2 Business account only - what the old tenant's Cloud Policy pushed, and what strands the user
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\SignIn (the GPO/ADMX branch, which is a different branch and will not be the one set here)
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Microsoft 365 Apps 16.0, any build that supports Cloud Policy service for Microsoft 365 (formerly Office cloud policy service / OCPS). Not present on Office 2013.
To undo
Set back to 2, or let the Cloud Policy service re-push on next check-in. To clear it properly, delete HKCU\Software\Policies\Microsoft\Cloud\Office\16.0 and HKCU\Software\Microsoft\Office\16.0\Common\CloudPolicy together.

What this costs you This is the branch the Cloud Policy service writes into, and it is NOT cleaned up when a device leaves a tenant or the user's licence is removed. The Click-to-Run service will rewrite it on the next check-in if the user still signs into a tenant that has the policy assigned, so on a genuinely-left tenant delete the whole branch rather than flipping the value. Deleting it will also drop every other cloud-pushed Office policy on that profile.

Source: learn.microsoft.com, github.com, office365itpros.com

Clear Internet\WebServiceCache\AllUsers

Found in the fieldUndocumented

Office activation or licensing lookups keep failing against a stale cached web-service response even after identities are cleared.

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers]
Key
HKCU\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers
What the values mean
  • present Cached responses from Office licensing/discovery web services are reused
  • absent Office re-queries the services at next launch
Branch
Preference
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 (Office 2016 onward); the equivalent exists under 15.0 for Office 2013.
To undo
No undo needed; the cache rebuilds itself. Export first if you want parity.

What this costs you Harmless but adds latency to the next few launches while the cache repopulates. It will NOT fix a licence that is genuinely missing in the tenant - if you clear this and the error persists unchanged, the problem is server-side, not cached.

Source: dennisspan.com

Saving, OneDrive and templates

Office defaulting to the cloud, template paths, trusted locations.

AllowNetworkLocations: trust UNC paths

Found in the field

A UNC trusted location is set but Excel still blocks macros, and the GPO-set 'Allow Trusted Locations on my network' keeps vanishing

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations" /v "AllowNetworkLocations" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations]
"AllowNetworkLocations"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations
Value
AllowNetworkLocations
Type
REG_DWORD
What the values mean
  • 0 Network/UNC trusted locations are not trusted (default)
  • 1 Permits network paths to be used as trusted locations
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Excel\Security\Trusted Locations
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 (15.0/14.0 identical). It is a single value on the PARENT Trusted Locations key, not inside each LocationNN subkey, and it is per application. ADMX label: 'Allow Trusted Locations on the network (not recommended)'.
To undo
Set to 0 or delete the value.

What this costs you This is the key field finding for MSPs: setting it in the POLICY branch is unreliable. On a Microsoft Q&A thread the GPO wrote allownetworklocations=1 into HKCU\SOFTWARE\Policies\...\excel\security\trusted locations but Excel did not consistently read it - the tick box cleared itself again after a minute. The reliable fix was writing it to the preference branch instead. Security-wise it genuinely weakens macro protection, so scope it to the apps that need it.

Source: learn.microsoft.com, ss64.com, devhut.net

AUTOSAVE-PATH / AutoRecoverPath: AutoRecover folder

Found in the field

AutoRecover files are being written to a roaming profile or redirected folder and I need them on a local disk

PowerShell
New-Item -Path 'HKCU:\Software\Microsoft\Office\16.0\Word\Options' -Force | Out-Null; New-ItemProperty -Path 'HKCU:\Software\Microsoft\Office\16.0\Word\Options' -Name 'AUTOSAVE-PATH' -PropertyType ExpandString -Value '%userprofile%\AppData\Roaming\Microsoft\Word' -Force | Out-Null
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options]
"AUTOSAVE-PATH"=hex(2):25,00,75,00,73,00,65,00,72,00,70,00,72,00,6f,00,66,00,69,00,6c,00,65,00,25,00,5c,00,41,00,70,00,70,00,44,00,61,00,74,00,61,00,5c,00,52,00,6f,00,61,00,6d,00,69,00,6e,00,67,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,5c,00,57,00,6f,00,72,00,64,00,00,00
Key
HKCU\Software\Microsoft\Office\16.0\Word\Options
Value
AUTOSAVE-PATH
Type
REG_EXPAND_SZ
What the values mean
  • 0 n/a - this is a path string, not a flag
  • 1 n/a
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Options
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0, and the value name is different in every app - Word: AUTOSAVE-PATH; Excel: AutoRecoverPath under Office\16.0\Excel\Options; PowerPoint: pathtoautorecoveryinfo under Office\16.0\PowerPoint\Options. All REG_EXPAND_SZ. Setting it for one app does not affect the others.
To undo
Delete the value; Office falls back to %AppData%\Microsoft\<App>.

What this costs you AutoRecover is NOT AutoSave - this changes where the every-10-minutes recovery file lands, not cloud AutoSave behaviour. Point it somewhere that always exists and is writable at launch; a missing or offline UNC path means no recovery files at all, which users only discover after a crash. Blue929's write-up sets Word in the preference branch but Excel and PowerPoint under SOFTWARE\Policies, so check both branches when a value appears to be ignored.

Source: blog.blue929.com

DOC-PATH / DefaultPath: default file location

Vendor documented

I need Word and Excel to default to the H: drive or a network folder instead of Documents or OneDrive

PowerShell
New-Item -Path 'HKCU:\Software\Microsoft\Office\16.0\Word\Options' -Force | Out-Null; New-ItemProperty -Path 'HKCU:\Software\Microsoft\Office\16.0\Word\Options' -Name 'DOC-PATH' -PropertyType ExpandString -Value 'the folder path, e.g. %HOMEDRIVE%%HOMEPATH%\Documents' -Force | Out-Null
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options]
"DOC-PATH"=hex(2):74,00,68,00,65,00,20,00,66,00,6f,00,6c,00,64,00,65,00,72,00,20,00,70,00,61,00,74,00,68,00,2c,00,20,00,65,00,2e,00,67,00,2e,00,20,00,25,00,48,00,4f,00,4d,00,45,00,44,00,52,00,49,00,56,00,45,00,25,00,25,00,48,00,4f,00,4d,00,45,00,50,00,41,00,54,00,48,00,25,00,5c,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,00,00
Key
HKCU\Software\Microsoft\Office\16.0\Word\Options
Value
DOC-PATH
Type
REG_EXPAND_SZ
What the values mean
  • 0 n/a - this is a path string, not a flag
  • 1 n/a
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Options
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for 2016/2019/2021/365; 15.0 for 2013. The value name differs per app and this catches people out: Word uses DOC-PATH under Word\Options, Excel uses DefaultPath under Excel\Options, and PowerPoint uses the Default value under HKCU\Software\Microsoft\Office\16.0\PowerPoint\RecentFolderList (you may have to create the RecentFolderList key first). All REG_EXPAND_SZ.
To undo
Delete the value; Office falls back to the Documents folder.

What this costs you Useless on its own if PreferCloudSaveLocations is 1 - Office ignores the default file location entirely and goes to OneDrive. Always set both. REG_EXPAND_SZ matters if you use %variables%; a plain REG_SZ will not expand.

Source: learn.microsoft.com, bonguides.com

Turn off Protected View for internet files

From my own field work

Documents from a trusted internal web application all open read-only in Protected View.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView" /v "DisableInternetFilesInPV" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\ProtectedView]
"DisableInternetFilesInPV"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView
Value
DisableInternetFilesInPV
Type
REG_DWORD
What the values mean
  • 0 Protected View applies to files from the internet (default)
  • 1 Protected View is skipped for them
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Security\ProtectedView
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2010 and later. Set it per app - Word, Excel and PowerPoint each have their own ProtectedView key.
To undo
Delete the value, or set it to 0.

Watch out Prefer adding the specific source as a Trusted Location or Trusted Site over disabling Protected View globally. This entry is here because it is widely asked for, not because it is a good default.

What this costs you Protected View is a real exploit mitigation. Turning it off means a malicious document from the internet or a mail attachment opens with full capability on the first click.

If the real problem is one internal application, fix it at the source: have it serve files from a path users reach over UNC, and trust that path instead.

Turn off Protected View for unsafe locations

Microsoft documented

Documents opened from the Temporary Internet Files or Downloaded Program Files folders open read-only in Protected View.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView" /v "DisableUnsafeLocationsInPV" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\ProtectedView]
"DisableUnsafeLocationsInPV"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView
Value
DisableUnsafeLocationsInPV
Type
REG_DWORD
What the values mean
  • 0 Protected View applies to files from unsafe locations (default)
  • 1 Protected View is skipped for them
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Security\ProtectedView
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2010 and later. Set per app; Word, Excel and PowerPoint each have their own ProtectedView key.
To undo
Delete the value, or set it to 0.

Watch out 'Unsafe locations' means the Downloaded Program Files and Temporary Internet Files folders by default, plus anything an administrator adds to the unsafe-locations list. It does NOT cover network shares: a share opening in Protected View is the separate internet-files or Mark-of-the-Web path, so add the share as a Trusted Location instead of reaching for this.

What this costs you Protected View is a real exploit mitigation. Turning it off means a malicious document from a share opens with full capability on the first click.

Pairs with DisableInternetFilesInPV, and the two are often set together without anyone checking which one actually matches the symptom. Confirm where the file is really coming from first.

Source: admx.help

DontAutoSave: turn AutoSave off by default

Community verifiedUndocumented

AutoSave keeps switching itself on for OneDrive and SharePoint files and users are overwriting originals

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Excel" /v "DontAutoSave" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel]
"DontAutoSave"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Excel
Value
DontAutoSave
Type
REG_DWORD
What the values mean
  • 0 AutoSave behaves normally (on by default for cloud files)
  • 1 AutoSave is off by default
Branch
Preference
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 Microsoft 365 Apps. Set it separately per app: HKCU\Software\Microsoft\Office\16.0\Word, \16.0\Excel and \16.0\PowerPoint. NOTE the value sits directly on the app key, NOT under \Options. Field reports from 2020 onward say it stopped working on newer 365 builds, so verify on the actual build before promising it.
To undo
Set to 0 or delete the value from each app key.

What this costs you Does not disable AutoRecover, and does not stop AutoSave being re-enabled per document by the user. Bob McKay's commenters report it reverting after a reboot, which is normally a GPO or a management agent rewriting the hive rather than Office. Commenters' attempts at 'autosavebydefaultadminchoice'/'autosavebydefaultuserchoice' did not work - do not propagate those names.

Source: professor-excel.com, bobmckay.com

EnableCloudOnlySaveAsMode: cloud-only Save As

Found in the fieldUndocumented

After an Office update Save As only offers cloud folders, or Save As to OneDrive leaves the file named Book1 and AutoSave errors

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO" /v "Enablecloudonlysaveasmode" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\FileIO]
"Enablecloudonlysaveasmode"=dword:00000000
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO
Value
Enablecloudonlysaveasmode
Type
REG_DWORD
What the values mean
  • 0 Keep the current local and cloud saving options
  • 1 Cloud only - restrict saving to cloud locations
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Microsoft 365 Apps 16.0, surfaced with the cloud-focused Save experience (~2025 builds). Exposed in ADMX as 'Restrict saving on non-Cloud locations' under User Configuration > Microsoft Office 2016 > Miscellaneous. Note this one lives under Common\FileIO, NOT Common\General like PreferCloudSaveLocations.
To undo
Set to 0, or delete the value to leave the policy unconfigured.

What this costs you Enabling it is implicated in real save failures: an MS Q&A reporter had Excel Save As to SharePoint leave the file as 'book1' and AutoSave fail with 'Something went wrong and we couldn't upload your document', with only Ctrl+S to an existing file working. Microsoft's answer on that thread concedes the value is not described in its own documentation. Set 0 (or clear it) when diagnosing odd Save As behaviour.

Source: office-watch.com, learn.microsoft.com

Hide cloud locations from Office

Found in the field

You want cloud save locations hidden from the Office interface entirely, not just deprioritised.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Internet" /v "OnlineStorage" /t REG_DWORD /d "3" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet]
"OnlineStorage"=dword:00000003
Key
HKCU\Software\Microsoft\Office\16.0\Common\Internet
Value
OnlineStorage
Type
REG_DWORD
What the values mean
  • 0 Default value - enables all services (all locations shown)
  • 1 Only OneDrive Personal locations are hidden
  • 2 Disables SharePoint Online and OneDrive for Business
  • 3 Disables SharePoint Online, OneDrive for Business, and OneDrive Personal
  • 4 Disables This PC
  • 8 Disables SharePoint On-Premises
  • 16 Disables Recent Places
  • 32 Disables SharePoint Online
  • 64 Disables OneDrive for Business
  • 128 Disables all third-party services
  • 4294967295 Disables all optional services
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\Internet
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2016 Professional through Microsoft 365 Apps (16.0); 15.0 for Office 2013. The ADMX equivalent is 'Hide file locations when opening or saving files' under User Configuration > Microsoft Office 2016 > Miscellaneous, and Microsoft's forum staff confirm it applies to Office 2016 as well as 365.
To undo
Set to 0 or delete the OnlineStorage value.

Watch out This is a sum of binary flags, not a list of choices, which is why 3 is simply 1+2. Add the flags for what you want hidden. Setting 4 hides This PC - do not include it by accident or you leave users with no local place to save. Values outside the listed flags are untested rather than a documented no-op.

What this costs you It is a SUM OF BINARY FLAGS, not an enum, which is why 3 = 1+2. Setting 4 removes 'This PC' - do not add it by accident or you strand users with no local save place. The policy only applies to Word, PowerPoint and Excel. No fetched source documents a defined fallback for arbitrary values; treat anything outside the listed flags as untested rather than 'policy off'.

Only applies to Word, Excel and PowerPoint. Microsoft's support article for this setting has been retired, so the flag table here is assembled from the ADMX definition and corroborating field write-ups rather than from a live Microsoft page. Pairs with UseOnlineContent, which governs whether Office reaches online for templates and help rather than which save locations appear.

Source: siderite.dev, pcworld.com, learn.microsoft.com

Move personal templates out of AppData

Vendor documented

The Personal tab in File > New is empty or says 'we had some trouble connecting to get templates'

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Word\Options" /v "PersonalTemplates" /t REG_EXPAND_SZ /d "C:\Templates" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options]
"PersonalTemplates"=hex(2):43,00,3a,00,5c,00,54,00,65,00,6d,00,70,00,6c,00,61,00,74,00,65,00,73,00,00,00
Key
HKCU\Software\Microsoft\Office\16.0\Word\Options
Value
PersonalTemplates
Type
REG_EXPAND_SZ
What the values mean
  • 0 n/a - this is a path string, not a flag
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Options
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0; set per app - the same value name exists under Office\16.0\Excel\Options and Office\16.0\PowerPoint\Options. Default is %USERPROFILE%\Documents\Custom Office Templates. Use REG_EXPAND_SZ instead of REG_SZ if the path contains %variables%.
To undo
Delete the value; Office reverts to the default Custom Office Templates folder.

What this costs you The classic failure in this thread was a localisation/legacy-name trap: the path must use 'Documents', not 'My Documents', or the Personal tab throws 'Sorry, we had some trouble connecting to get templates and can't show them right now'. Check BOTH branches when troubleshooting - a GPO-set value lands in Software\Policies\Microsoft\Office\16.0\Word\Options and wins over the preference copy, so editing Common\General or the preference key changes nothing.

A template folder outside the user's profile also needs a matching Trusted Location entry, or macros in those templates prompt every time. See the Trusted Locations entry.

Source: learn.microsoft.com

Stop Save As defaulting to the cloud

Found in the fieldUndocumented

Every Save As defaults to OneDrive or SharePoint and users keep saving company files to the wrong place.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\General" /v "PreferCloudSaveLocations" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General]
"PreferCloudSaveLocations"=dword:00000000
Key
HKCU\Software\Microsoft\Office\16.0\Common\General
Value
PreferCloudSaveLocations
Type
REG_DWORD
What the values mean
  • 0 Save to Computer by default; the per-app default file location is honoured
  • 1 OneDrive becomes the default save location and the default file location is ignored
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\General
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2016/2019/2021 and Microsoft 365 Apps (16.0). Use 15.0 for Office 2013. One value covers Word, Excel and PowerPoint. Microsoft's own Q&A confirms there is still NO ADMX policy for 'Save to computer by default', so registry is the only route even in a GPO shop.
To undo
Set to 1, or delete the value to return to Office's shipped behaviour (cloud-preferred).

What this costs you Setting 0 only changes the DEFAULT; users can still browse to OneDrive. It does not hide cloud locations - use OnlineStorage for that. yagmoth555 notes the preference-branch copy is user-writable ('The user can change that one'), so on unmanaged machines a user can flip it back via File > Options > Save.

Pair with DefaultSaveLocation if you want to point them at a specific path rather than merely away from OneDrive.

Source: bonguides.com, yagmoth555.wordpress.com, learn.microsoft.com, learn.microsoft.com

SkipOpenAndSaveAsPlace: bypass Backstage places

Vendor documented

I want Office to go straight to the normal file-picker dialog instead of the Backstage places screen

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\General" /v "SkipOpenAndSaveAsPlace" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General]
"SkipOpenAndSaveAsPlace"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\General
Value
SkipOpenAndSaveAsPlace
Type
REG_DWORD
What the values mean
  • 0 Show the Backstage places list on Open and Save As
  • 1 Skip the places list and go straight to the file browse dialog
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\General
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0; the equivalent UI tick is 'Don't show the Backstage when opening or saving files' in File > Options > Save. 15.0 for Office 2013.
To undo
Set to 0 or delete the value.

What this costs you Users lose the one-click Recent/OneDrive/SharePoint places list, which is unpopular with staff who live in SharePoint. Pair with OnlineStorage only when you genuinely want local-first behaviour; on its own it just changes which dialog appears first.

Source: helpcenter.cameyo.com

SkyDriveSignInOption: kill the save-time sign-in nag

Vendor documented

Office keeps nagging users to sign in to OneDrive when they save a file

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\General" /v "SkyDriveSignInOption" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General]
"SkyDriveSignInOption"=dword:00000000
Key
HKCU\Software\Microsoft\Office\16.0\Common\General
Value
SkyDriveSignInOption
Type
REG_DWORD
What the values mean
  • 0 Do not offer/prompt OneDrive sign-in during save
  • 1 Prompt the user to sign in to OneDrive and other cloud locations
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\General
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 (2016 through 365); 15.0 for Office 2013, where the ADMX name is 'Show OneDrive Sign In'. Legacy 'SkyDrive' naming survives in the value name years after the rename - do not 'correct' it to OneDrive.
To undo
Set to 1 or delete the value.

What this costs you Only suppresses the sign-in prompt in the save flow. It does not remove OneDrive as a place (OnlineStorage does) and does not sign anyone out. Harmless on standalone/retail installs.

Source: helpcenter.cameyo.com, learn.microsoft.com

Add a trusted location for a template share

From my own field work

Macros in a shared template folder prompt on every open, or a network template path is refused.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Word\Security\Trusted Locations\Location50" /v "Path" /t REG_SZ /d "C:\Templates" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\Trusted Locations\Location50]
"Path"="C:\\Templates"
Key
HKCU\Software\Microsoft\Office\16.0\Word\Security\Trusted Locations\Location50
Value
Path
Type
REG_SZ
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Word\Security\Trusted Locations\Location50
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2013 and later.
To undo
Delete the LocationNN key.

Watch out Pick a high LocationNN number such as 50 so you do not collide with the numbered entries Office ships or an administrator added. A UNC path also needs AllowNetworkLocations set to 1 on the parent Trusted Locations key, or it is ignored.

What this costs you Anything in a trusted location runs its macros without asking. Trust a folder users cannot write to, never a general-purpose share.

Set Description alongside Path so a later administrator can tell what the entry is for, and AllowSubFolders if the templates are nested.

Trusted Locations: pick a high LocationNN index

Community verified

I need to script a Trusted Location for a shared folder without clobbering the ones users already added

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations\Location50" /v "Path" /t REG_SZ /d "\\server\share\folder" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations\Location50]
"Path"="\\\\server\\share\\folder"
Key
HKCU\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations\Location50
Value
Path
Type
REG_SZ
What the values mean
  • 0 AllowSubFolders=0: only this folder is trusted
  • 1 AllowSubFolders=1: subfolders are trusted as well
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Excel\Security\Trusted Locations\Location50
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for 2016/2019/2021/365, 15.0 for 2013, 14.0 for 2010. Trusted Locations are PER APPLICATION - the subkey sits under Excel, Word, Access, PowerPoint or Publisher's own Security key, so a folder trusted for Excel is not trusted for Word. Subkeys are named Location, Location1, Location2 ... and each holds Path (REG_SZ, ending in a backslash), AllowSubFolders (REG_DWORD), Description (REG_SZ) and Date (REG_SZ).
To undo
Delete the LocationNN subkey, or remove it in File > Options > Trust Center > Trusted Locations.

Watch out Do not put a trailing backslash on the path in a reg add command: /d "C:\path\" makes Windows read the closing quote as escaped, so the argument never terminates and the switches that follow get swallowed into the value. Office accepts the path without it.

What this costs you The numbering is the trap: Office assigns Location1, Location2 ... in order as users manually trust documents, so a script that writes Location1 or Location2 will eventually collide with and silently overwrite a user's entry. Use a high index (30, 35, 50) that Office will not reach. A UNC or mapped-drive path additionally requires AllowNetworkLocations=1 on the parent Trusted Locations key or the entry is ignored. Prefer the UNC form over a mapped drive letter.

The trailing backslash on the path matters.

Source: ss64.com, devhut.net

UseOnlineContent: Office internet access level

Found in the field

Office says 'This feature has been disabled by your administrator' when a user clicks a cloud or online feature

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Internet" /v "UseOnlineContent" /t REG_DWORD /d "2" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet]
"UseOnlineContent"=dword:00000002
Key
HKCU\Software\Microsoft\Office\16.0\Common\Internet
Value
UseOnlineContent
Type
REG_DWORD
What the values mean
  • 0 Do not allow the user to access Office resources on the internet (disallowed to connect to the internet)
  • 1 Allow the user to opt in to access Office resources on the internet
  • 2 Default - allow the user to access Office resources on the internet
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\Internet
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for 2016/2019/2021/365; 15.0 for Office 2013 (same value name, same two locations).
To undo
Set to 2, or delete the value from both branches to return to default.

What this costs you This is the usual culprit behind 'disabled by your administrator' on OneDrive/SharePoint and template features after an over-zealous privacy or hardening script. Check the POLICY branch first: if UseOnlineContent exists under Software\Policies it overrides the preference copy and must be cleared there, not in Common\Internet.

Source: kunal-chowdhury.com, discourse.psappdeploytoolkit.com

Mail files and PSTs

Stopping PST sprawl without Group Policy.

SyncWindowSetting - the OST sync slider

Found in the field

Users' OST files are huge, or they complain mail older than a few weeks has vanished, and I have no GPO infrastructure to set the mail-to-keep-offline slider.

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Cached Mode" /v "SyncWindowSetting" /t REG_DWORD /d "12" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Cached Mode]
"SyncWindowSetting"=dword:0000000c
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Cached Mode
Value
SyncWindowSetting
Type
REG_DWORD
What the values mean
  • 0 All (entire mailbox) - when SyncWindowSettingDays is also 0
  • 1 1 month
  • 3 3 months
  • 6 6 months
  • 12 1 year
  • 24 2 years
  • 36 3 years (Outlook 2016+)
  • 60 5 years (Outlook 2016+)
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Cached Mode
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2013 introduced the slider (15.0); Outlook 2016+ (16.0) adds the day-level range via a second DWORD, SyncWindowSettingDays (3, 7 or 14). For Outlook 2016 both values must be present and one of them must be 0: SyncWindowSetting=0 + SyncWindowSettingDays=3 gives 3 days; SyncWindowSetting=6 + SyncWindowSettingDays=0 gives 6 months; both 0 gives All. If either is missing or invalid, Outlook 2016 defaults to SyncWindowSetting=12 and SyncWindowSettingDays=0.
To undo
Delete SyncWindowSetting and SyncWindowSettingDays to return the slider to the user and to Outlook's disk-size-based default.

What this costs you This value only lives in the Policies branch - there is no preference-branch equivalent, so writing it directly is how you do it without a domain. Because it is a policy value the slider becomes greyed out for the user. Shrinking the window does not shrink an existing OST immediately and a resync is involved; related value MaxLargeFileSize (REG_DWORD, in MB) under HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\PST caps the Unicode OST size (up to 50 GB on Outlook 2010+).

Source: practical365.com, support.microsoft.com

Block new PST files without Group Policy

From my own field work

Users keep making PST files and archiving mail out of the mailbox where nothing backs it up.

Command
reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\PST" /v "DisablePST" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\PST]
"DisablePST"=dword:00000001
Key
HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\PST
Value
DisablePST
Type
REG_DWORD
What the values mean
  • 0 PST files allowed (default)
  • 1 Users cannot add a PST to the profile
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\PST
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 and later.
To undo
Delete the value, or set it to 0.

What this costs you Existing PSTs already in the profile keep working; this stops new ones being added. It will also block legitimate PST imports, so turn it off before a migration that needs one.

Pairs with PSTDisableGrow. The point of using the preference branch rather than the policy branch is that it works on a workgroup machine with no domain at all.

ForceOSTPath - relocate new OST files

Found in the field

The OST is filling up C: (or sitting on a roaming profile / small SSD) and I need new accounts to cache somewhere else.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook" /v "ForceOSTPath" /t REG_EXPAND_SZ /d "D:\Documents\Outlook Files" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook]
"ForceOSTPath"=hex(2):44,00,3a,00,5c,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,5c,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00
Key
HKCU\Software\Microsoft\Office\16.0\Outlook
Value
ForceOSTPath
Type
REG_EXPAND_SZ
What the values mean
  • 0 n/a - this is a path string, not a flag
  • 1 n/a
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Outlook 2010 and later; 16.0 for 2016/2019/2021/2024/365, 15.0 for 2013.
To undo
Delete ForceOSTPath; new accounts go back to %LocalAppData%\Microsoft\Outlook. Existing OSTs stay where they were created.

What this costs you Applies to newly created ost-files only. Existing accounts keep their current OST, so to move an existing mailbox you must remove and re-add the account - which re-downloads the entire mailbox from the server. Set it BEFORE adding the account. The folder must exist and be writable by the user.

Any folder path; it is expandable, so %USERPROFILE% and friends work.

Source: robert365.com, slipstick.com

Freeze an existing PST at its current size

From my own field work

An existing PST keeps growing and you want to freeze it before a migration.

Command
reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\PST" /v "PSTDisableGrow" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\PST]
"PSTDisableGrow"=dword:00000001
Key
HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\PST
Value
PSTDisableGrow
Type
REG_DWORD
What the values mean
  • 0 PSTs can grow (default)
  • 1 Nothing new can be written into any PST
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\PST
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart Outlook
Applies to
Office 2013 and later.
To undo
Delete the value, or set it to 0.

What this costs you Outlook will throw errors on any rule, archive or manual move that targets a PST. Expect support calls if you set this without telling anyone.

Genuinely useful the night before a cutover: it stops users moving mail into a PST you are about to stop looking at.

Rendering and display

Blank panes, white flashes, redraw artefacts.

Turn off hardware graphics acceleration

Community verified

Office apps flash white, fail to redraw, or lock up when scrolling, especially over RDP or on a dock.

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Graphics" /v "DisableHardwareAcceleration" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Graphics]
"DisableHardwareAcceleration"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\Graphics
Value
DisableHardwareAcceleration
Type
REG_DWORD
What the values mean
  • 0 hardware graphics acceleration ENABLED (Office default)
  • 1 hardware graphics acceleration DISABLED - Office falls back to software rendering
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\Graphics
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for Office 2016/2019/2021 and Microsoft 365 Apps; 15.0 for Office 2013. The 'Disable hardware graphics acceleration' checkbox has been removed from the UI in recent Microsoft 365 Apps builds, which is exactly why the registry route matters now.
To undo
Set to 0 or delete the value, then restart the Office apps (a reboot is recommended when the Policies branch was used).

Watch out 1 disables acceleration. 0 enables it. The previous version of this page had 0 under a heading that said to turn acceleration off, which did the opposite of what it claimed.

What this costs you SETTLED: 1 DISABLES acceleration, 0 enables it. Any page saying 0 disables is wrong. The value name is a negative ('Disable...'), so 1 means 'yes, disable'. Which branch you pick matters: writing it under Software\Microsoft leaves the option changeable by the user; writing it under Software\Policies selects the checkbox and greys it out. Side effect of disabling: slower scrolling and rendering in large documents and on high-DPI displays, and PowerPoint transitions become choppy.

First thing to try on any display corruption complaint. Fixes a surprising share of them.

Source: learn.microsoft.com, woshub.com, learn.microsoft.com

DisableAnimations for smooth-typing lag

Found in the fieldUndocumented

Typing lags and the cursor smears in Word/Outlook over RDP or on a weak GPU

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Graphics" /v "DisableAnimations" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Graphics]
"DisableAnimations"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\Graphics
Value
DisableAnimations
Type
REG_DWORD
What the values mean
  • 0 Office animations and smooth typing on (default)
  • 1 animations, transitions and the smooth-typing cursor animation disabled
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\Graphics (same value name; use this branch to lock it)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Reboot
Applies to
15.0 for Office 2013 (where smooth typing was introduced), 16.0 for 2016/2019/2021 and Microsoft 365 Apps. Create the Graphics subkey if it is not there.
To undo
Set to 0 or delete the value.

What this costs you Separate from DisableHardwareAcceleration - field reports are explicit that turning hardware acceleration off does NOT stop the cursor animation, so on a lag complaint try both. The original source says a reboot (not just an app restart) is needed before it takes effect. Purely cosmetic downside.

Source: blog.jussipalo.com, docs.oracle.com

PowerPoint SlideShow acceleration off

Found in the field

PowerPoint slide shows tear, flicker or go black on the projector while the rest of Office is fine

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\PowerPoint\SlideShow" /v "DisableHardwareAcceleration" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\PowerPoint\SlideShow]
"DisableHardwareAcceleration"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\Office\16.0\PowerPoint\SlideShow
Value
DisableHardwareAcceleration
Type
REG_DWORD
What the values mean
  • 0 slide-show hardware acceleration enabled
  • 1 slide-show graphics acceleration disabled
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\PowerPoint\SlideShow
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
The source writes the version segment as a placeholder ("Office\xx\PowerPoint\SlideShow"); use 16.0 for 2016/2019/2021/365 and 15.0 for 2013. Verify on one machine.
To undo
Set to 0 or delete the value.

What this costs you Distinct from the suite-wide Common\Graphics value and often missed, so engineers disable suite acceleration unnecessarily when only slide shows misbehave. Disabling it makes transitions and video playback in presentations noticeably choppier.

Source: voltol.com

First-run and interface nags

Making Office stop asking.

DisableTelemetry 0x27100 that sticks

Found in the fieldUndocumented

OTeleData .etl files flood the disk on an RDS/Citrix box and DisableTelemetry=1 keeps resetting to 0

Command
reg add "HKCU\Software\Microsoft\Office\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d "160000" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry]
"DisableTelemetry"=dword:00027100
Key
HKCU\Software\Microsoft\Office\Common\ClientTelemetry
Value
DisableTelemetry
Type
REG_DWORD
What the values mean
  • 0 telemetry logging on; OTeleData_*.etl files are written
  • 1 nominally off, but Office rewrites this to 0 as soon as any Office app (notably Outlook) launches - this is the trap
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\15.0\osm (older Enablelogging / EnableUpload values; reported in the same thread as NOT fixing the .etl writes)
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Reported against Office 2013/2016-era Click-to-Run and MSI on Windows Server RDS. The path carries no version number (Office\Common\ClientTelemetry). Office Telemetry Dashboard has since been removed from Microsoft 365 Apps, so on current builds check whether .etl files are still being produced before applying this.
To undo
Delete the DisableTelemetry value or set it to 0.

What this costs you Completely undocumented magic number - nobody has explained why 0x27100 is not reverted while 1 is. Treat it as a workaround for a measured disk-I/O problem, not a privacy control: it stops the Telemetry Dashboard agent's .etl logging, not Office's modern diagnostic data (use SendTelemetry / the Policies clienttelemetry branch for that). Verify on one machine that the .etl files actually stop.

The value is often written as 0x00027100 in hex; reg add takes the decimal form, 160000.

Source: learn.microsoft.com

officeai TurnOffCallout hides Copilot

Found in the field

The Copilot button and its pop-up callout keep appearing in Word, Excel and Outlook

Command
reg add "HKCU\Software\Policies\Microsoft\office\16.0\common\officeai" /v "TurnOffCallout" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\office\16.0\common\officeai]
"TurnOffCallout"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\office\16.0\common\officeai
Value
TurnOffCallout
Type
REG_DWORD
What the values mean
  • 0 Copilot ribbon button and callout render (default)
  • 1 client does not render the Copilot popup or the ribbon button
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\office\16.0\common\officeai
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Reported effective from Microsoft 365 Apps version 2412 onward; "Older builds often ignore modern policies and require harder methods." There is a separate cloud-policy path for the Copilot app pin: HKCU\Software\Policies\Microsoft\Cloud\Office\16.0\common\copilot with CopilotPinning = 0 and PinningStateforCopilotApp = 0.
To undo
Delete TurnOffCallout or set it to 0.

What this costs you This is UI suppression only - it does not revoke the Copilot licence or stop the service, and a user with the licence can still reach Copilot by other entry points. Expect Microsoft to keep adding new entry points; re-check after major builds. Note this is HKCU under Policies, so it needs no local admin despite being a 'policy'.

Source: phinit.de

DisableBootToOfficeStart per app

Vendor documented

Word and Excel open the Start / recent-files screen instead of a blank document

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Word\Options" /v "DisableBootToOfficeStart" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options]
"DisableBootToOfficeStart"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Word\Options
Value
DisableBootToOfficeStart
Type
REG_DWORD
What the values mean
  • 0 show the Start screen (default)
  • 1 skip the Start screen and open a blank document
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\<app>\Options (ADMX-backed counterpart; the preference branch is what field guides use)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for Office 2016/2019/2021 and Microsoft 365 Apps; use 15.0 for Office 2013, where this screen first appeared. Set it per app - Word\Options, Excel\Options, PowerPoint\Options; a single value under 16.0\Common\General is also circulated and reported to cover all apps, but the per-app placement is the one with clean evidence.
To undo
Set to 0 or delete the value; the Start screen comes back on next launch.

What this costs you Harmless, but it also removes the recent-documents list users navigate by, so warn them. Does not affect Outlook.

Source: helpcenter.cameyo.com, itnator.net

FirstRun BootedRTM + disablemovie

Found in the fieldUndocumented

Every new user on this machine gets the Office first-run movie and welcome wizard

Command
reg add "HKCU\Software\Microsoft\Office\16.0\FirstRun" /v "BootedRTM" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\FirstRun]
"BootedRTM"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\FirstRun
Value
BootedRTM
Type
REG_DWORD
What the values mean
  • 0 first-run sequence has not been marked complete - the wizard/movie plays
  • 1 Office treats first run as already done and skips it (pair with disablemovie = 1)
Branch
Preference
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
The source demonstrates this on 15.0 (Office 2013) for an App-V package; the identical 16.0\FirstRun key is used in the field for 2016/2019/2021/365. Treat the 16.0 path as field-extrapolated from the 15.0 evidence, which is why confidence here is community-verified rather than documented.
To undo
Delete BootedRTM and disablemovie, or set both to 0.

What this costs you Per-user, so it must be written into the Default User hive or via a logon script / Active Setup to catch new profiles - writing it while logged on as the admin does nothing for anyone else. Setting BootedRTM without also handling shownfirstrunoptin and AcceptAllEulas usually just moves the nag rather than removing it.

Source: alkanesolutions.co.uk, helpcenter.cameyo.com

Policies clienttelemetry DisableTelemetry

Found in the fieldUndocumented

I want to cut Office telemetry on a standalone PC without a tenant or GPO

Command
reg add "HKCU\Software\Policies\Microsoft\office\common\clienttelemetry" /v "DisableTelemetry" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\office\common\clienttelemetry]
"DisableTelemetry"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\office\common\clienttelemetry
Value
DisableTelemetry
Type
REG_DWORD
What the values mean
  • 0 Office telemetry modules active (default)
  • 1 disables the Aria and Nexus Office telemetry modules
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\office\common\clienttelemetry
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Microsoft 365 Apps / Office 2016-2021. Note the path has no version number (office\common, not office\16.0\common), which is why it is often mistyped. HKLM equivalent of the same path is also reported in circulation.
To undo
Delete the DisableTelemetry value or set it to 0.

What this costs you Not acknowledged by Microsoft and not in the ADMX, so it can stop working on any build without notice - re-verify after major updates. It does NOT stop all Office data collection; the documented control for diagnostic-data level is SendTelemetry (1 = Required, 2 = Optional, 3 = Neither) under HKCU\Software\Policies\Microsoft\office\common\clienttelemetry. Writing to the Policies branch greys the related UI out for the user.

Source: ghacks.net

shownfirstrunoptin + AcceptAllEulas

Found in the fieldUndocumented

Office keeps showing the First Things First / opt-in and privacy dialog to every user

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\General" /v "shownfirstrunoptin" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General]
"shownfirstrunoptin"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\General
Value
shownfirstrunoptin
Type
REG_DWORD
What the values mean
  • 0 opt-in dialog has not been shown - Office shows it
  • 1 Office treats the opt-in as already shown and skips it
Branch
Preference
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Demonstrated on 15.0; the 16.0\Common\General path is the one used in the field for 2016-2021 and Microsoft 365 Apps. Pair with HKCU\Software\Microsoft\Office\16.0\Registration \"AcceptAllEulas\"=dword:00000001 and HKCU\Software\Microsoft\Office\16.0\Common\General \"ShownFileFmtPrompt\"=dword:00000001.
To undo
Delete shownfirstrunoptin or set it to 0.

What this costs you Per-user. Suppressing the opt-in does NOT choose a privacy setting for the user - it only stops the dialog, so the build's default diagnostic-data level stays in force. If you care about the actual data level, set it explicitly in the Policies privacy branch as well.

Source: alkanesolutions.co.uk, helpcenter.cameyo.com

UI Theme value and its numbers

Found in the fieldUndocumented

The Office theme is stuck or we need to force dark/black theme across a fleet

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common" /v "UI Theme" /t REG_DWORD /d "4" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common]
"UI Theme"=dword:00000004
Key
HKCU\Software\Microsoft\Office\16.0\Common
Value
UI Theme
Type
REG_DWORD
What the values mean
  • 0 Colorful
  • 1 see note - the attested values are 0, 3, 4 and 5 only; do not assume 1 and 2 are valid
  • 3 Dark Gray
  • 4 Black
  • 5 White
Branch
Preference
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office 2016/2019/2021 and Microsoft 365 Apps (16.0). Note the value name contains a SPACE - "UI Theme".
To undo
Set UI Theme back to the previous number, or let the user change it under File > Account > Office Theme.

What this costs you The big trap: on a signed-in Microsoft 365 account the theme also lives in a second, binary location under HKCU\Software\Microsoft\Office\16.0\Common\Roaming\{GUID-ADAL}\Settings\1186\{GUID}\Data, whose GUIDs differ per installation and activation. If roaming settings are on, that copy can overwrite your UI Theme edit at next sign-in - which is why 'I set the theme in the registry and it reverted' is such a common report. Either disable Office roaming settings as well or accept it is per-user-per-device.

Source: cloudappie.nl

WhatsNew SuppressForAutomation

From a Microsoft support caseUndocumented

What's New pop-ups keep appearing in Excel and Word after every Office update

Command
reg add "HKCU\Software\Microsoft\Office\Common\WhatsNew" /v "SuppressForAutomation" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\WhatsNew]
"SuppressForAutomation"=dword:00000001
Key
HKCU\Software\Microsoft\Office\Common\WhatsNew
Value
SuppressForAutomation
Type
REG_DWORD
What the values mean
  • 0 What's New dialogs show after updates (default)
  • 1 all What's New dialogs are suppressed
Branch
Preference
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Microsoft 365 Apps and Office 2016+. NOTE THE PATH HAS NO VERSION NUMBER - it is Office\Common\WhatsNew, not Office\16.0\Common\WhatsNew. Getting this wrong is the usual reason it 'does not work'.
To undo
Delete SuppressForAutomation or set it to 0.

What this costs you The widely-posted alternative is to hand-edit the version numbers under the same WhatsNew key, which has to be redone after every Office update; SuppressForAutomation is the durable form. No known side effects beyond users not being told about new features.

Source: learn.microsoft.com

shownfirstrunoptin: suppress the Opt-in Wizard

Community verified

"First things first" / Opt-in wizard appears on first launch of Word on every new profile, before the user can sign in or work.

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Common\General" /v "shownfirstrunoptin" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\General]
"shownfirstrunoptin"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Common\General
Value
shownfirstrunoptin
Type
REG_DWORD
What the values mean
  • 0 The Opt-in Wizard displays the first time the user runs an Office application
  • 1 The Opt-in Wizard does not display on first run
Branch
Both
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\General (ADMX "Disable Opt-in Wizard on first run", User Configuration > Microsoft Office 2016 > Privacy > Trust Center). Preference-branch counterpart: HKCU\Software\Microsoft\Office\16.0\Common\General with the same value name - that is the one to use with no GPO.
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Takes effect immediately
Applies to
16.0 for Office 2016+; the identical value under 15.0 for Office 2013. Office 2013's wider first-run set also includes HKCU\Software\Microsoft\Office\15.0\FirstRun with BootedRTM=1 and disablemovie=1.
To undo
Delete the value from whichever branch you set it in.

What this costs you Covers the old Opt-in / Customer Experience wizard only. On modern Microsoft 365 builds the blocking dialog at first launch is usually the privacy consent prompt instead - use the privacy keys for that. Be sceptical of HKCU\Software\Microsoft\Office\16.0\Registration \ AcceptAllEulas=1 being offered for this: the admin who tried it reported "But, I still see that window when launched first time." Because this lands in HKCU, it has to be written into the default user profile or run at logon to catch new profiles.

Source: learn.microsoft.com, msfn.org

Stop OneDrive or Lync launching at sign-in

From my own field workUndocumented

OneDrive or Skype for Business launches itself at every sign-in on machines that do not use them.

Command
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "OneDrive" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=-
Key
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value
OneDrive
Type
REG_SZ
Branch
Preference
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
All versions.
To undo
OneDrive recreates the Run entry when it next runs and updates, so this is not permanent.

Watch out This is a delete rather than a set: remove the value, do not blank it. The same Run key holds the Lync entry.

What this costs you OneDrive stops syncing until something starts it. If the machine relies on Known Folder Move, do not do this.

OneDrive is persistent about putting this back after an update. For a durable result use the OneDrive policy keys rather than the Run key.

Update channels and Click-to-Run

Pinning, moving and unsticking builds.

CDNBaseUrl channel GUIDs

Found in the field

I need to move this PC from Current Channel to Monthly Enterprise / Semi-Annual without the ODT or GPO

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "CDNBaseUrl" /t REG_SZ /d "http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"CDNBaseUrl"="http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
CDNBaseUrl
Type
REG_SZ
What the values mean
  • 5440fd1f-7ecb-4221-8110-145efaa6372f Beta Channel (was: Insider / Insider Fast)
  • 64256afe-f5d9-4f86-8936-8840a6a4f5be Current Channel (Preview) (was: Monthly Channel Targeted / Insider Slow)
  • 492350f6-3a01-4f97-b9c0-c7c6ddf67d60 Current Channel (was: Monthly Channel)
  • 55336b82-a18d-4dd6-b5f6-9e5095c314a6 Monthly Enterprise Channel (new in 2020, no old name)
  • b8f9b850-328d-4355-9145-c59439a0c4cf Semi-Annual Enterprise Channel (Preview) (was: Semi-Annual Channel Targeted)
  • 7ffbc6bf-bc32-4f92-8982-f9dd17fd3114 Semi-Annual Enterprise Channel (was: Semi-Annual Channel / Broad / Deferred)
Branch
Preference
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate (value: updatepath, REG_SZ, takes the same GUID URL)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Click-to-Run 16.0 only. STALE-NAME WARNING: Microsoft renamed the channels on 9 June 2020. OfficeC2RClient.exe /changesetting Channel=Broad is pre-2020 syntax; 'Broad' was the ODT attribute for what is now Semi-Annual Enterprise Channel, and the current ODT/switch tokens are BetaChannel, CurrentPreview, Current, MonthlyEnterprise, SemiAnnualPreview, SemiAnnual. Monthly Enterprise Channel did not exist before 2020 and therefore has no legacy token at all, which is why scripts written against the old names cannot reach it.
To undo
Write the previous GUID URL back, or re-run the ODT with the correct Channel attribute.

What this costs you Change CDNBaseUrl alone and the client may keep updating from the old channel until the Office Automatic Updates 2.0 scheduled task runs. Field reports are consistent that CDNBaseUrl goes stale after an ODT-driven channel change, so do not use it alone to AUDIT the channel - read UpdateChannel for that. Pointing CDNBaseUrl at a channel whose build is older than the installed build does not roll Office back on its own.

Source: blog.scho.kr, iamsysadmin.eu, configgirl.com, blog.eriteach.com

TargetVersion / UpdateToVersion build pin

Found in the field

Office refuses to update past one specific build and reports it is up to date

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "TargetVersion" /t REG_SZ /d "delete the value to unpin" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"TargetVersion"="delete the value to unpin"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
TargetVersion
Type
REG_SZ
What the values mean
  • 0 n/a - a build string such as 16.0.14430.20342; present = pinned
  • 1 n/a - absent = free to take the channel's latest build
Branch
Both
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate (value: updatetargetversion, REG_SZ)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Click-to-Run 16.0. A closely related value, UpdateToVersion, is left behind in the same Configuration key by some Office Deployment Tool runs and has the same pinning effect; check for both.
To undo
Re-create the value with the build string you want to pin to, or set updatetargetversion in the policy branch.

What this costs you This is the number-one cause of 'Office says it is up to date but it is six versions behind'. It is often left behind by a one-off ODT rollback that nobody documented, so it survives long after the reason for it is gone. Clearing it lets the machine jump many builds at once - expect a long update and a forced app shutdown.

Source: fixitect.com, isladogs.co.uk, michlstechblog.info

C2R UpdateChannel is the real channel

Found in the field

Office is on the wrong update channel and OfficeC2RClient.exe /changesetting Channel=... does nothing

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "UpdateChannel" /t REG_SZ /d "http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"UpdateChannel"="http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
UpdateChannel
Type
REG_SZ
What the values mean
  • http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 Current Channel
  • http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6 Monthly Enterprise Channel
  • http://officecdn.microsoft.com/pr/7ffbc6bf-bc32-4f92-8982-f9dd17fd3114 Semi-Annual Enterprise Channel
  • http://officecdn.microsoft.com/pr/b8f9b850-328d-4355-9145-c59439a0c4cf Semi-Annual Enterprise Channel (Preview)
  • http://officecdn.microsoft.com/pr/64256afe-f5d9-4f86-8936-8840a6a4f5be Current Channel (Preview)
  • http://officecdn.microsoft.com/pr/5440fd1f-7ecb-4221-8110-145efaa6372f Beta Channel
Branch
Preference
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate (value: updatebranch)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Click-to-Run Office 2016/2019/2021/LTSC and Microsoft 365 Apps (16.0). Not applicable to MSI Office 2013/15.0, which has no ClickToRun\Configuration key of this shape.
To undo
Set UpdateChannel (and CDNBaseUrl) back to the previous GUID URL, or re-run the Office Deployment Tool with the desired Channel attribute, which rewrites both.

What this costs you This is the key an MSP actually has to change when /changesetting Channel= silently does nothing. Traps: (a) if a value exists under HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate it wins and your edit is reverted on the next Office launch or scheduled-task run; (b) set UpdateChannel WITHOUT also setting CDNBaseUrl and the client can report one channel while pulling content from another - field scripts always set BOTH to the same GUID URL; (c) a value named UnmanagedUpdateUrl is visible in this same Configuration key on some machines and is widely deleted as part of 'channel keeps reverting' fixes, but I found it only in a forum screenshot with no sourced description of its behaviour, so treat deleting it as unverified folklore and export the key first. Microsoft's own channel guidance says UpdateChannel is managed dynamically by the Office Automatic Updates 2.0 scheduled task and should not be hand-edited; in the field it is edited anyway, together with CDNBaseUrl, then forced with OfficeC2RClient.exe /update user.

Source: forum.bigfix.com, blog.eriteach.com, configgirl.com, learn.microsoft.com

UpdateChannelChanged pending-change flag

Found in the fieldUndocumented

I changed the channel in the registry but nothing happens - how do I tell if the engine noticed?

Nothing to set here. This entry explains how the setting behaves so you can read what you find on a machine.

Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
UpdateChannelChanged
Type
REG_SZ
What the values mean
  • 0 False - no channel change pending; the last change completed
  • 1 True - the update engine has seen a pending channel change and will act on the next successful update
Branch
Preference
Scope
All users on the machine, needs an elevated prompt
To take effect
Takes effect immediately
Applies to
Click-to-Run 16.0.
To undo
Nothing to revert; it is engine state. Deleting UpdateDetectionLastRunTime under HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Updates forces immediate re-detection.

What this costs you Read-only diagnostic - do not set it by hand. If it stays False after you edit UpdateChannel, your edit was overridden (policy or UnmanagedUpdateUrl) or the Office Automatic Updates 2.0 scheduled task is disabled. The engine accepts one channel change at a time and needs a successful update before it will take another, so a stuck True means the previous change never finished.

Office writes this itself after a channel switch. It is here so you recognise it on a machine, not because you should set it. Office writes this itself, so there is nothing here for you to set; it is listed so you recognise it when reading a machine.

Source: configgirl.com

UpdatesEnabled True/False in C2R config

Found in the field

Office updates are greyed out or disabled and I cannot find the GPO that did it

Command
reg add "HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /v "UpdatesEnabled" /t REG_SZ /d "True" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration]
"UpdatesEnabled"="True"
Key
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
Value
UpdatesEnabled
Type
REG_SZ
What the values mean
  • 0 "False" - Click-to-Run updates are off (this is what the Office UI 'Disable Updates' button writes)
  • 1 "True" - Click-to-Run updates are on
Branch
Preference
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate (value: enableautomaticupdates, REG_DWORD)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Click-to-Run 16.0.
To undo
Set the string back to False, or click Disable Updates in the Office UI.

What this costs you Note the type - it is a REG_SZ holding the literal words True/False, not a DWORD. Technicians habitually create a DWORD here and then wonder why nothing changed. If the policy-branch enableautomaticupdates is also set, it wins.

Source: isladogs.co.uk, michlstechblog.info

updatebranch policy without GPO

Found in the field

I want to pin the update channel on a workgroup PC with no Active Directory

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate" /v "updatebranch" /t REG_SZ /d "Current" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate]
"updatebranch"="Current"
Key
HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate
Value
updatebranch
Type
REG_SZ
What the values mean
  • 0 n/a - string value. Modern tokens reported in the field: Current, MonthlyEnterprise, SemiAnnual (also seen as Deferred), CurrentPreview / FirstReleaseCurrent, SemiAnnualPreview / FirstReleaseDeferred, BetaChannel
  • 1 n/a
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Restart the Office app
Applies to
Subscription Click-to-Run only (Microsoft 365 Apps, subscription Project/Visio). STALE-VALUE WARNING: widely-linked guides from the Office 2016 era list the accepted strings as Insiderfast / FirstReleaseCurrent / Current / Validation / Business. 'Business' (= old Deferred Channel) and 'Validation' are pre-2020 tokens and there was no 'MonthlyEnterprise' token at all, which is the other half of why old channel scripts cannot reach Monthly Enterprise Channel. Sources disagree on whether the Semi-Annual token today is 'SemiAnnual' or 'Deferred', so verify on one machine before you push it.
To undo
Delete the updatebranch value (and the OfficeUpdate key if you created it), then run "OfficeC2RClient.exe /update user" from C:\Program Files\Common Files\Microsoft Shared\ClickToRun.

What this costs you This value outranks everything in ClickToRun\Configuration, so it is both the fix for 'my channel change keeps reverting' and the cause of it. It also blocks Microsoft 365 Apps Cloud Update from taking management of the device. Setting a token the build does not recognise can leave the client with no valid channel and no updates at all.

Source: tomtalks.blog, imab.dk, blog.eriteach.com, forum.bigfix.com

updatedeadline forced-update countdown

Found in the field

Office pops a countdown telling users it will force-close their apps to update

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate" /v "updatedeadline" /t REG_SZ /d "delete the value to stop the countdown" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate]
"updatedeadline"="delete the value to stop the countdown"
Key
HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate
Value
updatedeadline
Type
REG_SZ
What the values mean
  • 0 n/a - a date/time string (e.g. 06/15/2026 13:30); present = Office will force-apply the update at that time and nag beforehand
  • 1 n/a - absent = no deadline, updates apply when the user allows
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\Common\OfficeUpdate
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Takes effect immediately
Applies to
Click-to-Run 16.0 (Microsoft 365 Apps). Lives in the same OfficeUpdate policy key as updatebranch, updatepath, updatetargetversion and enableautomaticupdates.
To undo
Re-create the value with the desired deadline string.

What this costs you This is the usual culprit behind 'Office keeps telling my client it will close their apps' on a machine that was once managed by an RMM, ODT run or an old GPO that nobody owns any more. Its presence - along with updatebranch, updatepath, updatetargetversion and enableautomaticupdates - also blocks Microsoft 365 Apps Cloud Update from taking management of the device, so if you are moving a client to Cloud Update the whole set has to go. Deleting it does not disable updates; it only removes the enforced deadline.

Source: blog.eriteach.com

Pin Windows to a feature-update version

From my own field work

Windows keeps offering or installing a feature update you are not ready for, and you need machines held on a known version.

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "TargetReleaseVersion" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"TargetReleaseVersion"=dword:00000001
Key
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value
TargetReleaseVersion
Type
REG_DWORD
What the values mean
  • 0 Not pinned
  • 1 Honour TargetReleaseVersionInfo
Branch
Policy
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Reboot
Applies to
Windows 10 1803 and later, and Windows 11. Requires a Pro, Enterprise or Education edition; Home ignores it.
To undo
Delete both values to resume normal feature updates.

Watch out Set TargetReleaseVersionInfo alongside this, as a REG_SZ naming the version to hold, for example 23H2. An earlier version of this page pinned 21H2, which is now out of support - whatever you pin, put a date in your calendar to revisit it.

What this costs you A machine pinned to a version that has reached end of servicing stops receiving security updates. This is the trap: the pin keeps working long after the version it names has stopped being supported.

Pair: TargetReleaseVersion (REG_DWORD 1) switches the pin on, TargetReleaseVersionInfo (REG_SZ) names the version. Not an Office key, but it belongs next to the Office update keys because it is the other half of keeping a fleet on a known build.

OneDrive sync client

Silent configuration, Known Folder Move, Files On-Demand.

DisableFileSyncNGSC: the OneDrive kill switch

Community verified

OneDrive will not start, nothing happens when you click it, and OneDrive has vanished from File Explorer and Office save locations

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\OneDrive" /v "DisableFileSyncNGSC" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OneDrive]
"DisableFileSyncNGSC"=dword:00000000
Key
HKLM\SOFTWARE\Policies\Microsoft\Windows\OneDrive
Value
DisableFileSyncNGSC
Type
REG_DWORD
What the values mean
  • 0 OneDrive permitted
  • 1 Prevent the usage of OneDrive for file storage - sync client will not launch and OneDrive disappears as a save location
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Windows\OneDrive
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Sign out and back in
Applies to
Windows 10/11 and Server 2016+, independent of the Office version. GPO label: Computer Configuration > Administrative Templates > Windows Components > OneDrive > 'Prevent the usage of OneDrive for file storage'.
To undo
Delete the DisableFileSyncNGSC value (preferred) or set it to 0, then sign out and back in.

What this costs you Be precise about the path - this one sits under Policies\Microsoft\WINDOWS\OneDrive, whereas every OneDrive sync-app policy (FilesOnDemandEnabled, SilentAccountConfig, KFM*) sits under Policies\Microsoft\OneDrive with no Windows segment. Confusing the two is the commonest reason 'the registry fix didn't work'. This is also the #1 thing left behind by Windows 10 privacy/debloat scripts and by old images, and it is what makes OneDrive silently do nothing. Field advice is to DELETE the value rather than set it to 0, because people report it reverting to 1. Setting it to 1 also removes OneDrive from Office's Save As places entirely.

Source: learn.microsoft.com, winhelponline.com

EnableAllOcsiClients: Office-OneDrive sync handoff

Vendor documented

The OneDrive Office tab's 'Use Office applications to sync Office files that I open' box is greyed out or I need it off

Command
reg add "HKCU\SOFTWARE\Policies\Microsoft\OneDrive" /v "EnableAllOcsiClients" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\OneDrive]
"EnableAllOcsiClients"=dword:00000000
Key
HKCU\SOFTWARE\Policies\Microsoft\OneDrive
Value
EnableAllOcsiClients
Type
REG_DWORD
What the values mean
  • 0 Disables 'Use Office applications to sync Office files that I open' and hides the Office tab in OneDrive settings
  • 1 Office desktop apps handle sync of open Office files, enabling co-authoring and sharing from the apps
Branch
Policy
Policy equivalent: HKCU\SOFTWARE\Policies\Microsoft\OneDrive
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
OneDrive sync app with Office 2016/2019 or Microsoft 365 Apps. ADMX label: 'Coauthor and share in Office desktop apps'. Note this OneDrive policy is written under HKCU here even though most OneDrive policies are HKLM - Microsoft's own documentation presents it as a Computer Configuration policy, so you may see it in both hives.
To undo
Set to 1 or delete the value, then reset OneDrive.

What this costs you Setting 0 is a blunt instrument: it turns off the Office/OneDrive handoff, which also disables AutoSave and real-time co-authoring for that user, and it is reached for far too readily when the real problem is a corrupt Office file cache. Microsoft announced the 'Enable OCSI for Tenants' policy is being REMOVED (rollout from April 2025) so that AutoSave and co-authoring work properly - treat this key as legacy and verify on current builds before deploying it. OneDrive must be reset or restarted for the change to register.

Source: learn.microsoft.com, learn.microsoft.com

FilesOnDemandEnabled: control Files On-Demand

Found in the field

Office files sometimes fail to save because they are online-only placeholders, or I need Files On-Demand forced on or off

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\OneDrive" /v "FilesOnDemandEnabled" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\OneDrive]
"FilesOnDemandEnabled"=dword:00000001
Key
HKLM\SOFTWARE\Policies\Microsoft\OneDrive
Value
FilesOnDemandEnabled
Type
REG_DWORD
What the values mean
  • 0 Disable Files On-Demand - content is downloaded and kept local
  • 1 Enable Files On-Demand - new users see online-only files and content downloads on open
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\OneDrive
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Sign out and back in
Applies to
OneDrive sync app on Windows 10, Windows 11 and Server 2016+. Version-independent of Office. GPO label: Computer Configuration > Administrative Templates > OneDrive > 'Use OneDrive Files On-Demand'.
To undo
Delete the value to return the decision to the user/OneDrive default.

What this costs you Type matters - it MUST be a REG_DWORD, not a REG_QWORD. HalfOnCloud calls wrong-typed values a known issue in environments migrating from SCCM/MECM, where the OneDrive client silently ignores the policy. Turning Files On-Demand OFF forces every synced file local and can blow out disk usage; turning it ON is a standard first diagnostic when Office reports save failures against placeholder files. Note the path has no Windows segment, unlike DisableFileSyncNGSC.

Source: acceptdefaults.com, halfoncloud.com

KFMSilentOptIn: Known Folder Move without GPO

Found in the field

I need Desktop, Documents and Pictures redirected into OneDrive on a handful of PCs with no Active Directory or GPO

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\OneDrive" /v "KFMSilentOptIn" /t REG_SZ /d "the Microsoft 365 tenant GUID" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\OneDrive]
"KFMSilentOptIn"="the Microsoft 365 tenant GUID"
Key
HKLM\SOFTWARE\Policies\Microsoft\OneDrive
Value
KFMSilentOptIn
Type
REG_SZ
What the values mean
  • 0 n/a - the data is a tenant ID string, not a flag
  • 1 n/a
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\OneDrive
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Sign out and back in
Applies to
OneDrive sync app, any Office version. Companions in the same key: KFMSilentOptInWithNotification (REG_DWORD 1) to notify the user afterwards, KFMOptInWithWizard (REG_SZ tenant ID) to prompt instead of acting silently, and KFMBlockOptIn (REG_DWORD 1) to suppress Microsoft's backup prompts entirely.
To undo
Delete the value to stop future redirection; folders already redirected must be moved back manually through OneDrive settings (Backup > Manage backup > Stop backup).

What this costs you Silent KFM only fires if the user is already signed in, so it needs SilentAccountConfig in effect first; otherwise nothing happens and there is no error. The value is a string holding the tenant GUID, not a 1 - a DWORD 1 here does nothing. This is a per-machine policy key you write by hand on no-AD sites; it takes effect at Windows sign-in, not when OneDrive.exe restarts. Redirecting Desktop can surprise users whose shortcuts move.

Source: malcolmplested.co.uk, cinchops.com, halfoncloud.com

SilentAccountConfig: auto sign-in OneDrive

Found in the field

OneDrive never signs itself in, there are no sign-in logs, and KFM/silent setup does nothing

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\OneDrive" /v "SilentAccountConfig" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\OneDrive]
"SilentAccountConfig"=dword:00000001
Key
HKLM\SOFTWARE\Policies\Microsoft\OneDrive
Value
SilentAccountConfig
Type
REG_DWORD
What the values mean
  • 0 User must sign in to OneDrive manually
  • 1 Silently sign in the user to the OneDrive sync app with their Windows credentials
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\OneDrive
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Sign out and back in
Applies to
OneDrive sync app on Entra-joined/hybrid Windows; independent of Office version. Related keys in the same hive: AllowTenantList, which must be a SUBKEY containing the tenant ID as a named value, not a flat string on the OneDrive key.
To undo
Set to 0 or delete the value; existing signed-in accounts stay signed in.

What this costs you Two field traps. First, type: it must be REG_DWORD, not REG_QWORD, or OneDrive ignores it - common after SCCM/MECM-written values. Second, restarting OneDrive.exe is not enough: silent config is triggered during the Windows logon sequence, so the user has to sign out of Windows and back in. Success is observable at HKCU\Software\Microsoft\OneDrive (SilentBusinessConfigCompleted = 1) and HKCU\Software\Microsoft\OneDrive\Accounts\Business1 (UserEmail, ConfiguredTenantId, SilentAuthSucceeded) - a useful read-only check before you start changing things.

Source: halfoncloud.com, malcolmplested.co.uk

Office document cache and Upload Center

Stuck uploads, corrupt cache, the Upload Center nobody wants.

AgeOutPolicy: days to keep cached documents

Microsoft documented

OfficeFileCache has grown to gigabytes and is filling the SSD or the roaming profile

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO" /v "ageoutpolicy" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\FileIO]
"ageoutpolicy"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO
Value
ageoutpolicy
Type
REG_DWORD
What the values mean
  • 0 Delete documents after they have been closed for an hour
  • 1 Keep cached documents for 1 day (default is 14)
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0. A sibling value, ageoutpolicyincludingfilespendingupload, governs files that still have pending changes or upload errors - from Version 2512 Office retains those for up to 365 days by default, which is the real reason caches balloon. Both live in the same FileIO policy key.
To undo
Delete the value to return to the 14-day default.

What this costs you Microsoft's article does not state the data type for these values; they are numeric ADMX settings so REG_DWORD is what the templates write - verify against an ADMX-configured machine before scripting it fleet-wide. Files older than the limit are only removed when nothing is pending upload, so a stuck upload defeats the setting entirely. Aggressive values push re-downloads and hurt co-authoring.

The data is a number of days.

Source: support.microsoft.com

DisableLongTermCaching: empty cache on close

Vendor documented

Office Document Cache keeps corrupting on an RDS/Citrix box and I want files dropped from the cache as soon as they close

Command
reg add "HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO" /v "disablelongtermcaching" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\FileIO]
"disablelongtermcaching"=dword:00000001
Key
HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO
Value
disablelongtermcaching
Type
REG_DWORD
What the values mean
  • 0 Disabled - documents stay in the Office Document Cache after closing
  • 1 Enabled - Office immediately deletes files from the Office Document Cache when a document is closed
Branch
Policy
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\FileIO
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
16.0 for 2016/2019/2021/365; the same value name works at 15.0 and 14.0. ADMX label: 'Delete files from Office Document Cache' under User Configuration > Microsoft Office 2016 > Microsoft Office Document Cache. This is the registry equivalent of the Upload Center tick 'Delete files from the Office Document Cache when they are closed'.
To undo
Set to 0 or delete the value.

What this costs you Microsoft explicitly does not recommend it: disabling long-term caching affects file reopen and upload behaviour, especially for recently co-authored files, and SharePoint Workspace will not work correctly with it enabled. It is a policy-branch-only value, so on a no-GPO machine you are writing into Software\Policies by hand and it will be stripped if a GPO later manages the key.

Source: learn.microsoft.com, support.microsoft.com, admx.newyard.nl

DisableNotificationIcon: hide Upload Center tray icon

Found in the fieldUndocumented

The Office Upload Center tray icon and 'Upload failed' balloons keep bothering users

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\FileIO" /v "DisableNotificationIcon" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\FileIO]
"DisableNotificationIcon"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Common\FileIO
Value
DisableNotificationIcon
Type
REG_DWORD
What the values mean
  • 0 Show the Upload Center icon in the notification area
  • 1 Hide the Upload Center notification-area icon
Branch
Preference
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
Reported at 16.0, 15.0 (Office 2013) and 14.0 (Office 2010) with the same value name under Common\FileIO. Largely moot on current Microsoft 365 builds, where the Upload Center is replaced by the in-app 'Files Needing Attention' experience - but still live on 2013/2016/2019 estates.
To undo
Set to 0 or delete the value and sign out/in.

What this costs you Cosmetic only. It hides the icon; it does NOT stop OfficeSyncProcess.exe running or stop uploads failing, so you lose the user's only visible warning that a file never reached SharePoint. Do not use it to paper over a genuine upload failure. The source writes the path as HKU\Software\...; that is the same place as HKCU\Software\... for the logged-on user.

Source: ghacks.net

EnableRealtimeChannel: fix SP2013 file locking

Vendor documented

Word 2016 locks documents on an on-prem SharePoint 2013 library - 'locked for editing by another user' - and co-authoring fails

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\FileIO" /v "EnableRealtimeChannel" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\FileIO]
"EnableRealtimeChannel"=dword:00000000
Key
HKCU\Software\Microsoft\Office\16.0\Common\FileIO
Value
EnableRealtimeChannel
Type
REG_DWORD
What the values mean
  • 0 Disable the real-time co-authoring channel - Word stops locking files on SharePoint 2013/2010
  • 1 Real-time channel enabled (default); only works against SharePoint Online and OneDrive
Branch
Preference
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Office/Word 2016 (16.0) against SharePoint 2013 or 2010 on-premises. Originates with the October 13 2015 Office 2016 update (KB2920679 / KB3100925 troubleshooting article). Not needed for SharePoint Online.
To undo
Set to 1 or delete the value and restart Word.

What this costs you Turns off real-time co-authoring for that user everywhere, including SharePoint Online libraries, so only deploy it where the on-prem farm is the problem. Beware conflicting advice in the wild: one Microsoft Q&A thread tells users to make the value 1, which is the opposite of the KB fix - the KB sets it to 0 to stop the locking.

Source: ftduarte.blogspot.com, support.microsoft.com

Delete Common\FileIO to rebuild the Office cache

Community verifiedUndocumented

'The Microsoft Upload Center found a problem while accessing the Office Document Cache and needs to repair it' keeps coming back, or files silently fail to save

Command
reg delete "HKCU\Software\Microsoft\Office\16.0\Common\FileIO" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\FileIO]
Key
HKCU\Software\Microsoft\Office\16.0\Common\FileIO
What the values mean
  • 0 n/a - this is a key deletion, not a flag
  • 1 n/a
Branch
Preference
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
16.0 (Office 2016 / 365 ProPlus, confirmed on 16.0.7766.2099 and 16.0.8201.2213) and 15.0 for Office 2013. The classic repeat-offender environments are Citrix PVS, RDS/XenApp and roaming/UPM profiles where multiple OfficeFileCache folders pile up.
To undo
Nothing to revert - Office recreates the key and a fresh OfficeFileCache folder on next launch. Keep the renamed Old_OfficeFileCache until users confirm no lost work.

What this costs you Anything still pending upload in the cache is lost, so check Upload Center for pending files first. Two variants circulate - one thread deletes HKCU\...\Office\16.0\FileIO, the confirmed-working one for 365 ProPlus deletes HKCU\...\Office\16.0\Common\FileIO. Close every Office app and the Upload Center (OfficeSyncProcess) first or the keys are recreated immediately. On Citrix, exclude the cache directory from profile sync or it comes straight back.

Clearing the key is only half of it: also close the Office apps and delete or rename %LocalAppData%\Microsoft\Office\16.0\OfficeFileCache, which is where the cached content actually lives.

Source: learn.microsoft.com

Teams and Skype for Business

Stopping them installing, starting and re-adding themselves.

preventteamsinstall in OfficeUpdate

Found in the field

Teams keeps reappearing on machines every time Office updates itself

Command
reg add "HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\common\officeupdate" /v "preventteamsinstall" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Office\16.0\common\officeupdate]
"preventteamsinstall"=dword:00000001
Key
HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\common\officeupdate
Value
preventteamsinstall
Type
REG_DWORD
What the values mean
  • 0 Teams may be installed with new Office installs and Office updates (default)
  • 1 Teams is not installed with a new Office installation or an Office update
Branch
Policy
Policy equivalent: HKLM\SOFTWARE\Policies\Microsoft\Office\16.0\common\officeupdate
Survives a policy refresh
Yes
Scope
All users on the machine, needs an elevated prompt
To take effect
Takes effect immediately
Applies to
Microsoft 365 Apps Click-to-Run 16.0. Explicitly the route for "Microsoft 365 Apps for business" or anyone who "can't use Group Policy" - i.e. the no-AD case.
To undo
Delete preventteamsinstall or set it to 0.

What this costs you Prevents re-installation; it does not remove a Teams that is already there. Will not stop new Teams arriving by other channels (Windows Update / Store provisioning on Windows 11). Note the value sits in the OfficeUpdate key, which is the same key where a stray updatebranch or updatetargetversion can break your updates - check what else is in there while you are in it.

Source: itcrumbs.com, michlstechblog.info

Resiliency DoNotDisableAddinList

Found in the field

Outlook keeps disabling the Teams Meeting add-in every few days and users lose the Teams Meeting button

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList" /v "TeamsAddin.FastConnect" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList]
"TeamsAddin.FastConnect"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList
Value
TeamsAddin.FastConnect
Type
REG_DWORD
What the values mean
  • 0 add-in is subject to Outlook's slow-load performance monitoring and can be auto-disabled
  • 1 add-in is exempt from Outlook's performance monitoring and will not be auto-disabled
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Resiliency\DoNotDisableAddinList (ADMX-backed 'List of managed add-ins' counterpart; field guides use the preference branch)
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Outlook 2016/2019/2021 and Microsoft 365 Apps classic Outlook. The value NAME is the add-in's ProgID, and the DATA is the flag - an easy thing to get backwards.
To undo
Delete the TeamsAddin.FastConnect value from DoNotDisableAddinList.

What this costs you Fix the LoadBehavior first: HKCU\SOFTWARE\Microsoft\Office\Outlook\Addins\TeamsAddin.FastConnect \"LoadBehavior\" must be 3. Adding the exemption without fixing LoadBehavior leaves the add-in still not loading. Exempting an add-in from resiliency monitoring means a genuinely broken or slow add-in will now hang Outlook startup instead of being quarantined - this is the trade-off. Also clear any existing entries under Outlook\Resiliency\DisabledItems and CrashingAddinList, or the add-in stays disabled from its history.

Source: rain-city.tech, learn.microsoft.com

Remove the 'lync' Run value

Community verified

Skype for Business starts at logon for every user no matter how many times we untick the box

Command
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "lync" /t REG_SZ /d "delete the value" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"lync"="delete the value"
Key
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value
lync
Type
REG_SZ
What the values mean
  • 0 value absent - Skype for Business does not autostart
  • 1 value present (path to lync.exe) - Skype for Business autostarts
Branch
Preference
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
Skype for Business 2015/2016 desktop client (the Office 16.0-era lync.exe). Not applicable to Teams.
To undo
Re-tick 'Automatically start the app when I log on to Windows' in Skype for Business Options > Personal, which rewrites the value.

What this costs you The client RE-CREATES this value whenever a user re-enables autostart in Options > Personal, and it is created fresh per profile at first launch - which is why a one-time delete never sticks. The field answer is to deploy it as a recurring registry DELETE item (Group Policy Preferences, or a scheduled task / RMM script on non-AD machines) so it is removed at every logon and policy refresh. On Windows 10/11 also check Settings > Accounts > Sign-in options > 'Use my sign-in info to automatically... reopen my apps', which relaunches SfB independently of this value.

Source: learn.microsoft.com, adamfowlerit.com

New Teams MSIX StartupTask State

Found in the fieldUndocumented

New Teams starts at logon and the old Run-key and startup-folder tricks have no effect

Command
reg add "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MSTeams_8wekyb3d8bbwe\TeamsTfwStartupTask" /v "State" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MSTeams_8wekyb3d8bbwe\TeamsTfwStartupTask]
"State"=dword:00000001
Key
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MSTeams_8wekyb3d8bbwe\TeamsTfwStartupTask
Value
State
Type
REG_DWORD
What the values mean
  • 0 also reported in the field as a 'disabled' state written by Intune/PowerShell remediations alongside a LastDisabledTime update - treat as disabled but less well attested than 1
  • 1 Disabled - the app will not launch at user login
  • 2 Enabled - the app will launch at user login
Branch
Preference
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
New Teams (MSTeams MSIX/AppX package, MSTeams_8wekyb3d8bbwe). OBSOLETE-METHOD WARNING: classic Teams has been retired, so the familiar fixes are dead - removing "com.squirrel.Teams.Teams" from HKCU\Software\Microsoft\Windows\CurrentVersion\Run, editing %APPDATA%\Microsoft\Teams\desktop-config.json, and uninstalling the Teams Machine-Wide Installer by its MSI product GUID all apply only to the old Squirrel/MSI client. New Teams is removed with Remove-AppxPackage / Remove-AppxProvisionedPackage, not msiexec.
To undo
Set State to 2 (enabled), or re-enable Teams under Settings > Apps > Startup.

What this costs you Sources disagree on whether the disabled state is 1 or 0 - the fetched article is explicit that 1 = disabled and 2 = enabled, while some Intune remediation scripts write 0 and also stamp LastDisabledTime. Test on one machine and confirm against Settings > Apps > Startup. The key lives under Software\Classes\Local Settings, which is in UsrClass.dat, not NTUSER.DAT, so Default-User-hive templating does not reach it and roaming-profile solutions behave differently. Writing it for 'all users' needs per-profile loading of UsrClass.dat.

Source: leeejeffries.com, techcommunity.microsoft.com

Teams PreventFirstLaunchAfterInstall

Found in the field

Teams launches itself the first time each new user logs on after it is installed

Command
reg add "HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\Teams" /v "PreventFirstLaunchAfterInstall" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Office\16.0\Teams]
"PreventFirstLaunchAfterInstall"=dword:00000001
Key
HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\Teams
Value
PreventFirstLaunchAfterInstall
Type
REG_DWORD
What the values mean
  • 0 Teams starts automatically at the user's next logon after install (default)
  • 1 Teams does not start automatically for a user who has never started it
Branch
Policy
Policy equivalent: HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\Teams
Survives a policy refresh
Yes
Scope
The signed-in user only
To take effect
Sign out and back in
Applies to
Office 16.0 policy branch; written for the Teams-with-Office deployment path.
To undo
Delete the value or set it to 0.

What this costs you ORDER MATTERS: it only works if it is in place BEFORE Teams is installed, and it only covers users who have never launched Teams. Once a user has started Teams once, Teams configures itself to start at the next logon and this value no longer helps - at that point you need the MSIX StartupTask State value instead. It is HKCU, so it must be deployed per user or into the Default User hive before install.

Source: office365itpros.com

The new Outlook toggle

Holding the line on classic Outlook.

HideNewOutlookToggle removes the switch

Found in the field

Users keep flipping the 'Try the new Outlook' toggle and losing their PST data files and add-ins

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Options\General" /v "HideNewOutlookToggle" /t REG_DWORD /d "1" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\General]
"HideNewOutlookToggle"=dword:00000001
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Options\General
Value
HideNewOutlookToggle
Type
REG_DWORD
What the values mean
  • 0 the 'Try the new Outlook' toggle is shown (default)
  • 1 the toggle is hidden from classic Outlook
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\office\16.0\outlook\options\general
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Classic Outlook 2016/2019/2021 and Microsoft 365 Apps. Does not apply to new Outlook itself.
To undo
Set to 0 or delete the value; the toggle returns on next Outlook start.

What this costs you Hides the entry point only - it does not uninstall new Outlook, block the automatic migration, or move mailbox data. To also stop the forced migration, field guides pair it with HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences \"UseNewOutlook\"=0, deletion of NewOutlookAutoMigrationStage / NewOutlookAutoMigrationType under Options\General and NewOutlookRenudgeStartDate / NewOutlookRenudgeWatermark under Preferences, plus HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Preferences \"NewOutlookMigrationUserSetting\"=0. Microsoft re-adds the nudge values on later builds, so this needs re-applying.

Source: cloudclients.co.uk, slipstick.com, pdq.com, edi.wang

UseNewOutlook = 0 forces classic

Found in the field

Outlook auto-migrated itself to new Outlook and the user wants classic back

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences" /v "UseNewOutlook" /t REG_DWORD /d "0" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Preferences]
"UseNewOutlook"=dword:00000000
Key
HKCU\Software\Microsoft\Office\16.0\Outlook\Preferences
Value
UseNewOutlook
Type
REG_DWORD
What the values mean
  • 0 use classic Outlook
  • 1 use new Outlook
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Outlook\Preferences (value: NewOutlookMigrationUserSetting = 0, to block the migration itself)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Classic Outlook 2016/2019/2021 and Microsoft 365 Apps on Windows.
To undo
Set UseNewOutlook to 1 to go back to new Outlook.

What this costs you On its own this is only a one-shot flip - the auto-migration will flip it back to 1 on a later build unless you also clear the migration-stage values under HKCU\Software\Microsoft\Office\16.0\Outlook\Options\General (NewOutlookAutoMigrationStage, NewOutlookAutoMigrationType), delete the HKCU\Software\Microsoft\Office\16.0\Outlook\NewOutlook key, and set NewOutlookMigrationUserSetting = 0 in the Policies branch. On machines where classic Outlook has already been removed, setting this to 0 just leaves the user with no working client - check that outlook.exe is still installed first.

Source: slipstick.com, edi.wang, cloudclients.co.uk

Telemetry and connected experiences

Diagnostic data and the consent prompts.

Suppress privacy notice dialog

Vendor documentedUndocumented

Every user gets the 'Your privacy option' / optional connected experiences notice on first launch

Command
reg add "HKCU\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous" /v "OptionalConnectedExperiencesNoticeVersion" /t REG_DWORD /d "2" /f
As a .reg file
Save as a .reg file
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous]
"OptionalConnectedExperiencesNoticeVersion"=dword:00000002
Key
HKCU\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous
Value
OptionalConnectedExperiencesNoticeVersion
Type
REG_DWORD
What the values mean
  • 0 notice not yet acknowledged - Office shows it
  • 1 an older notice version was acknowledged; current builds re-show the dialog
  • 2 current notice version marked as already shown - dialog suppressed
Branch
Preference
Policy equivalent: HKCU\Software\Policies\Microsoft\Office\16.0\Common\Privacy (values: ControllerConnectedServicesEnabled, DisconnectedState, UserContentDisabled, DownloadContentDisabled)
Survives a policy refresh
No. If Group Policy manages this setting it will overwrite your value on the next refresh.
Scope
The signed-in user only
To take effect
Restart the Office app
Applies to
Microsoft 365 Apps / Office 2019+ builds that carry the privacy-notice dialog.
To undo
Delete the value; the notice reappears on next launch.

What this costs you This only hides the NOTICE - it does not disable optional connected experiences. If the goal is actually to turn them off, set ControllerConnectedServicesEnabled in the Policies privacy branch (reported as 1 = allowed, 2 = disabled) instead of, or as well as, this. The version number is build-dependent, so a future Office build may bump it and the dialog returns once.

Source: helpcenter.cameyo.com

Share your thoughts, leave a comment

Your email address will not be published. Required fields are marked *

You may also like these

INFOSTRUCTION

You're about to become an infostruction VIP!

By subscribing, you’ll receive a monthly round-up of the latest news. There’ll be no spam, I promise :)