From eb9598b2ed7fe1638259c0b53da2f82cdc48f0d8 Mon Sep 17 00:00:00 2001
From: Sam Ramon <15154970+samantharamon@users.noreply.github.com>
Date: Thu, 30 Jul 2026 10:37:23 +0930
Subject: [PATCH 1/2] [Outlook] (decryption) Document decryption improvements
in preview (#5813)
* Draft post-MVP features
* Document support for unified manifest
* Apply fix from review
* Apply suggestion from review
* Document additional behavior
* Appy suggestion from review
* Update ms.date
---
docs/develop/event-based-activation.md | 4 +-
docs/outlook/encryption-decryption.md | 155 ++++++++++++++++++++++++-
2 files changed, 154 insertions(+), 5 deletions(-)
diff --git a/docs/develop/event-based-activation.md b/docs/develop/event-based-activation.md
index 6c69f27f9..05ba32f1f 100644
--- a/docs/develop/event-based-activation.md
+++ b/docs/develop/event-based-activation.md
@@ -1,7 +1,7 @@
---
title: Activate add-ins with events
description: Learn how to develop an Office Add-in that implements event-based activation.
-ms.date: 06/23/2026
+ms.date: 07/30/2026
ms.topic: concept-article
ms.localizationpriority: medium
---
@@ -72,7 +72,7 @@ Support for this feature in Outlook was introduced in [requirement set 1.10](/ja
|`OnSensitivityLabelChanged`|sensitivityLabelChanged|On changing the sensitivity label while composing a message or appointment. To learn how to manage the sensitivity label of a mail item, see [Manage the sensitivity label of your message or appointment in compose mode](../outlook/sensitivity-label.md).
Event-specific data object: [SensitivityLabelChangedEventArgs](/javascript/api/outlook/office.sensitivitylabelchangedeventargs)|[1.13](/javascript/api/requirement-sets/outlook/outlook-requirement-set-1-13)
- Web browser
- Windows ([new](https://support.microsoft.com/office/656bb8d9-5a60-49b2-a98b-ba7822bc7627) and classic1)
- New Mac UI2
|
|`OnMessageReadWithCustomAttachment`|Not available|On opening a message that contains a specific attachment type in read mode.|[Preview](/javascript/api/requirement-sets/outlook/outlook-requirement-set-preview)4|
|`OnMessageReadWithCustomHeader`|Not available|On opening a message that contains a specific internet header name in read mode.|[Preview](/javascript/api/requirement-sets/outlook/outlook-requirement-set-preview)4|
-|`OnMessageDecrypt`|Not available|On matching the header of an encrypted message to the header key in an add-in's manifest. To learn more, see [Create an encryption Outlook add-in](../outlook/encryption-decryption.md).|[1.16](/javascript/api/requirement-sets/outlook/outlook-requirement-set-1-16)- Web browser
- Windows ([new](https://support.microsoft.com/office/656bb8d9-5a60-49b2-a98b-ba7822bc7627) and classic1)
|
+|`OnMessageDecrypt`|messageDecrypt|On matching the header of an encrypted message to the header key in an add-in's manifest. To learn more, see [Create an encryption Outlook add-in](../outlook/encryption-decryption.md).|[1.16](/javascript/api/requirement-sets/outlook/outlook-requirement-set-1-16)- Web browser
- Windows ([new](https://support.microsoft.com/office/656bb8d9-5a60-49b2-a98b-ba7822bc7627) and classic1)
|
> [!NOTE]
> 1 Event-based add-ins in classic Outlook on Windows require a minimum of Windows 10 Version 1903 (Build 18362) or Windows Server 2019 Version 1903 to run.
diff --git a/docs/outlook/encryption-decryption.md b/docs/outlook/encryption-decryption.md
index 65a2ee941..b547e82fe 100644
--- a/docs/outlook/encryption-decryption.md
+++ b/docs/outlook/encryption-decryption.md
@@ -1,7 +1,7 @@
---
title: Create an encryption Outlook add-in
description: Learn how to develop an Outlook add-in that encrypts and decrypts messages.
-ms.date: 06/23/2026
+ms.date: 07/30/2026
ms.topic: how-to
ms.localizationpriority: medium
---
@@ -53,8 +53,87 @@ The `OnMessageDecrypt` event is supported on the Message Read surface. Support v
### Configure the manifest
+# [Unified manifest for Microsoft 365](#tab/jsonmanifest)
+
> [!NOTE]
-> The `OnMessageDecrypt` event can currently only be implemented with an add-in only manifest.
+> The `OnMessageDecrypt` event and `"extensions.autoRunEvents.events.options.headerName"` property are in preview with the unified manifest. Don't use the decryption feature with the unified manifest in a production add-in.
+
+In your add-in's **manifest.json** file, you must configure the [`"extensions.runtimes"`](/microsoft-365/extensibility/schema/extension-runtimes-array) array and add the [`"extensions.autoRunEvents"`](/microsoft-365/extensibility/schema/element-extensions#autorunevents) array to enable event-based activation in your add-in.
+
+1. Add the following object to the `"extensions.runtimes"` array. Note the following about this markup.
+
+ - The `"id"` of the runtime is set to the descriptive name `"autorun_runtime"`.
+ - The `"code"` property has a child `"page"` property that is set to an HTML file and a child `"script"` property that is set to a JavaScript file. Office uses one of these values depending on the platform.
+ - Outlook on the web and the [new Outlook on Windows](https://support.microsoft.com/office/656bb8d9-5a60-49b2-a98b-ba7822bc7627) execute the handler in a browser runtime, which loads an HTML file. That file, in turn, contains a `