JatzoOnline Security
JATZO GUIDE

Rolling out Jatzo for Outlook across your team

How an administrator deploys the Jatzo add-in to everyone in Microsoft 365, what it can access, and how scan allowances work across a team.

Choose the explanation that suits you. Both versions cover the same topic.

1. What your people get

Jatzo appears in Outlook as a button on an open message. Somebody reads an email they are unsure about, presses it, and a panel explains in plain English whether the message looks safe and exactly which warning signs it found. Nothing is scanned automatically and nothing happens until a person asks for it. On a work or school mailbox the panel can be pinned open, at which point it follows whichever email they click, so it stays in front of them rather than being something they have to remember exists. Microsoft limit pinning to Microsoft 365 work and school accounts, so on a personal Outlook.com mailbox there is no pin and each email is checked with the button. Nothing else differs: the same checks run on the same evidence and produce the same score whichever kind of mailbox it is.

2. What Jatzo can and cannot see

The add-in asks Outlook for read access to the message a person is looking at when they press the button, and nothing else. It cannot reply, forward, delete, move or change anything in a mailbox, it cannot reach other messages, and it cannot read anything nobody asked it to check. The message is analysed and released: Jatzo keeps the subject, the score and the verdict for the case history, and does not retain the message body, the full links, the addresses or any attachment content.

3. What you need before you start

Deploying to your whole organisation needs three things: a Microsoft 365 subscription that includes Exchange Online, which means a Business or Enterprise plan rather than a standalone Exchange licence; the Global Administrator or Exchange Administrator role; and active mailboxes for the people you are deploying to. If you only want to try it on your own mailbox first, none of that applies, and you can add it yourself from your account page in a minute.

4. Get the add-in file

Sign in to Jatzo, open your account page, and find Your organisation. Under Staff domains, list the email domains your staff use and save them. Then, under Roll Jatzo out to everyone, press Create the deployment file and download it. Treat this file as a key rather than a document: anyone holding it can have Jatzo set up for a mailbox at those domains. Keep it with your other deployment material rather than emailing it around, and if you ever need to withdraw it, create a replacement, which stops the old one setting up anybody new.

5. Prove the domains are yours

Jatzo asks you to prove you own each domain you listed, because a list anybody can type is not evidence. Your account page shows one short DNS record for each domain: publish it wherever your DNS is managed, then press Check the record. Until a domain is proved, Jatzo will not set itself up for a Gmail mailbox at it, and after the date shown on the page it stops setting up Outlook mailboxes at it too. People already set up carry on working either way. If the record is ever removed you get a month of warning before new setups stop, and putting it back clears it.

6. Deploy it from the admin centre

In the Microsoft 365 admin centre, open Settings, then Integrated apps. Near the top of that page there is an Add-ins link: open it, choose Deploy Add-in, and pick the file you downloaded. Assign it to yourself first while you check it, then widen it to a group or to the whole organisation once you are happy. Microsoft usually rolls a new add-in out within a few minutes, though it can take up to twelve hours to reach everybody, so give it time before assuming something is wrong.

7. Your staff do not set anything up

There is nothing for them to do. Create the deployment file on your Jatzo account page, listing the email domains your staff use, and upload that file in step 6. The first time somebody opens the panel it recognises their mailbox and sets Jatzo up for them: no account, no password, no code, no setup screen. The account this creates cannot be signed in to on the Jatzo website, so there is no password for anyone to lose or leak, and each person can be removed on their own in Team administration. They do not see a Disconnect option, because the add-in was set up for them rather than by them. The file only works for mailboxes at the domains you listed, so it is no use to anyone outside your organisation, and you can replace it at any time without interrupting people already using it.

8. Allowances, and what happens when somebody leaves

Every check your staff run comes out of your team allowance, not out of anything they buy themselves. It is one shared monthly pool rather than a separate allowance each, so a quiet month for one person leaves more for everybody else. Your team has as many places as you set on your Jatzo account, where you can add more at any time. Jatzo stops setting up new people once every place is in use, rather than quietly adding places to your bill. When somebody leaves, remove them in Team administration: that ends their access immediately. Removing the add-in in Microsoft 365 stops the button appearing but does not by itself end their access, so do both.

9. If something does not appear

Give it a few hours before troubleshooting, then check three things in order. Whether the person has an Exchange Online mailbox, because an unlicensed account has nowhere for the add-in to load. Whether they are looking at an open message, since the button only exists there. And whether they are on a supported Outlook, meaning current Outlook for Windows or Mac, or Outlook on the web. If the panel opens but reports that it could not start, that is usually a network rule between them and Jatzo rather than the add-in itself. If the button is there but the panel will not pin on a work mailbox, the installed file is an older one: an add-in added from a file never updates itself, so remove it and add the current file again.