{"id":25882,"date":"2026-06-30T08:00:02","date_gmt":"2026-06-30T15:00:02","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/?p=25882"},"modified":"2026-07-02T17:23:59","modified_gmt":"2026-07-03T00:23:59","slug":"mailbox-requirement-set-1-16-now-available-for-outlook-add-ins","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/mailbox-requirement-set-1-16-now-available-for-outlook-add-ins\/","title":{"rendered":"Mailbox requirement set 1.16 now available for Outlook add-ins"},"content":{"rendered":"<p><a href=\"https:\/\/learn.microsoft.com\/javascript\/api\/requirement-sets\/outlook\/outlook-requirement-set-1-16\">Mailbox requirement set 1.16<\/a> is now generally available for Outlook add-ins. This release reflects our continued investment in closing the gap between COM\/VSTO and web add-ins, with a focus on message and information security.<\/p>\n<p>Mailbox 1.16 introduces APIs and platform updates that enable your add-in to:<\/p>\n<ul>\n<li>Decrypt protected messages and attachments in an event-based workflow.<\/li>\n<li>Determine whether Exchange Web Services (EWS) tokens are supported in an organization.<\/li>\n<li>Easily identify inline attachments in mail items.<\/li>\n<li>Retrieve a larger number of recipients from mail items.<\/li>\n<li>Store more session-scoped state and data with a larger SessionData limit.<\/li>\n<\/ul>\n<h2>Handle message decryption with ease<\/h2>\n<p>Mailbox requirement set 1.16 introduces the <a href=\"https:\/\/learn.microsoft.com\/office\/dev\/add-ins\/outlook\/encryption-decryption\">OnMessageDecrypt<\/a> event, which enables Outlook add-ins to automatically decrypt protected messages when a user opens them. The event-based workflow identifies encrypted messages, decrypts messages, displays the decrypted message content, and surfaces error notifications when needed. This workflow handles the operational steps so that you can focus on defining and implementing encryption and decryption protocols that meet your organization\u2019s security requirements in the add-in.<\/p>\n<p>To learn more about implementing decryption in your add-in, see <a href=\"https:\/\/learn.microsoft.com\/office\/dev\/add-ins\/outlook\/encryption-decryption\">Create an encryption Outlook add-in<\/a>. To see a sample decryption add-in in action, try out the <a href=\"https:\/\/github.com\/OfficeDev\/Office-Add-in-samples\/tree\/main\/Samples\/outlook-encrypt-decrypt-messages\">Encrypt and decrypt messages in Outlook sample<\/a>.<\/p>\n<h2>Detect support for EWS tokens in an organization<\/h2>\n<p>While EWS tokens have been turned off for Exchange Online environments, some organizations still run on-premises environments. With the introduction of the <a href=\"https:\/\/learn.microsoft.com\/javascript\/api\/outlook\/office.diagnostics#outlook-office-diagnostics-ews-member\">Office.context.mailbox.diagnostics.ews.getTokenStatusAsync<\/a> API, your add-in can now identify whether EWS callback tokens are supported in an organization. This enables your add-in to run the recommended authentication solutions when available while maintaining backward compatibility when needed.<\/p>\n<h2>Enhance data loss prevention and content processing workflows<\/h2>\n<p>Mailbox 1.16 also enhances existing APIs to support data loss prevention and content processing scenarios.<\/p>\n<ul>\n<li>The <a href=\"https:\/\/learn.microsoft.com\/javascript\/api\/requirement-sets\/outlook\/outlook-requirement-set-1-16#api-list\">contentId<\/a> property expands the attachment API so your add-in can easily identify inline attachments in mail items during content inspection and rendering workflows.<\/li>\n<li>The <a href=\"https:\/\/learn.microsoft.com\/javascript\/api\/outlook\/office.recipients#outlook-office-recipients-getasync-member(1)\">getAsync<\/a> method of the Recipients API now returns up to 1,000 recipients from any recipient field of a mail item. This expanded limit helps your data loss prevention solutions evaluate larger recipient lists in a single operation.<\/li>\n<li>The <a href=\"https:\/\/learn.microsoft.com\/javascript\/api\/outlook\/office.sessiondata\">SessionData<\/a> object now supports up to 2,621,440 characters per add-in, so that your add-in can store and retrieve data more seamlessly within a single session.<\/li>\n<\/ul>\n<p>Try the new Mailbox 1.16 capabilities in your Outlook add-in today. Happy coding!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mailbox requirement set 1.16 is now generally available for Outlook add-ins. This release reflects our continued investment in closing the gap between COM\/VSTO and web add-ins, with a focus on message and information security. Mailbox 1.16 introduces APIs and platform updates that enable your add-in to: Decrypt protected messages and attachments in an event-based workflow. [&hellip;]<\/p>\n","protected":false},"author":69076,"featured_media":25884,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,11],"tags":[132,168,12,298],"class_list":["post-25882","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-365-developer","category-office-add-ins","tag-add-ins","tag-office-javascript-api","tag-outlook","tag-outlook-add-ins"],"acf":[],"blog_post_summary":"<p>Mailbox requirement set 1.16 is now generally available for Outlook add-ins. This release reflects our continued investment in closing the gap between COM\/VSTO and web add-ins, with a focus on message and information security. Mailbox 1.16 introduces APIs and platform updates that enable your add-in to: Decrypt protected messages and attachments in an event-based workflow. [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/25882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/users\/69076"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/comments?post=25882"}],"version-history":[{"count":2,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/25882\/revisions"}],"predecessor-version":[{"id":25885,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/25882\/revisions\/25885"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media\/25884"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media?parent=25882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/categories?post=25882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/tags?post=25882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}