Updated May 27, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
New Outlook for Windows now supports Lightweight Directory Access Protocol (LDAP) directories for S/MIME certificate lookup. This enables tenants to configure LDAP directories for their organization as well as enabling users to configure LDAP directories themselves. Once configured, users can find recipients’ public encryption certificates from the directories when sending encrypted email, improving secure collaboration with external partners. This is especially valuable for tenants who collaborate with external partners and rely on public/partner LDAP directories to store public S/MIME certificates of users.
This message is associated with Microsoft 365 Roadmap ID 518287.
[When this will happen:]
- General Availability (Worldwide): We will begin rolling out in late May 2026 and expect to complete by mid-June 2026 (previously late May).
- General Availability (GCC): We will begin rolling out in mid-June 2026 (previously early June) and expect to complete by late June 2026.
[How this affects your organization:]
Who is affected:
- Organizations that use S/MIME encryption with external recipients whose public certificates are hosted in third-party LDAP directories
- Admins managing Exchange Online
What will happen:
- Admins can configure LDAP directories using Exchange Online PowerShell.
- Users can add LDAP directories in Settings > Mail > S/MIME in new Outlook.
- When composing an S/MIME encrypted email, users can select recipients from the LDAP directory via the To field. This will directly enable Outlook to retrieve the certificate from the selected LDAP directory. If users add a recipient directly to the ‘To list’, Outlook will scan all available certificate sources, including the configured LDAP directories.
- LDAP endpoints must not require authentication, as authentication is not currently supported.
- Feature is enabled by default once available.
- No impact to:
- Classic Outlook for Windows users
- Organizations not using LDAP for S/MIME certificate discovery
Screenshot: “Add LDAP directory” option in Settings > Mail > S/MIME and LDAP recipient picker in the To field during message composition:
[What you can do to prepare:]
- No action is required to enable this feature
- If your organization uses LDAP for S/MIME certificates:
- Identify LDAP directory endpoints used by your organization
- Run the Add-LdapDirectory cmdlet to register a new directory:
Add-LdapDirectory -Organization "contoso.com" -Id "corp-ldap" -Host "ldap.corp.com" -Port 636 -UseSsl - Configure directories using Exchange Online PowerShell (Add-LdapDirectory).
- Ensure LDAP endpoints do not require authentication.
- Communicate guidance to users transitioning to new Outlook: Set up Outlook to use S/MIME encryption | Microsoft Support.
Learn more: Configure S/MIME in Exchange Online | Microsoft Learn (will be updated before we complete rollout)
[Compliance considerations:]
No compliance considerations identified, review as appropriate for your organization.
Source: Microsoft
<<< [MC1310680] Archive
Tooltip: View earlier revisions of this post
Latest Posts
- [Action Required] Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport [MC1323250]
![[Action Required] Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport [MC1323250] 2 pexels earano 3608311](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Amazon SageMaker HyperPod Slurm clusters now support specifying minimum capacity requirements with continuous provisioning

- (Updated) Microsoft Teams: Rule-based enablement of Microsoft 365 third-party apps in the Teams admin center [MC1085133]
![(Updated) Microsoft Teams: Rule-based enablement of Microsoft 365 third-party apps in the Teams admin center [MC1085133] 4 pexels tirachard kumtanom 112571 347139](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Contact Center – Update to provide greater granularity to session rejection reasons [MC1324072]
![Dynamics 365 Contact Center – Update to provide greater granularity to session rejection reasons [MC1324072] 5 puppet 1636124 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
![(Updated) New Outlook for Windows: LDAP support for S/MIME certificate lookup [MC1310680] 1 (Updated) New Outlook for Windows: LDAP support for S/MIME certificate lookup [MC1310680]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-eye4dtail-134402-1024x683.webp)
![[Action Required] Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport [MC1323250] 2 pexels earano 3608311](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-earano-3608311-150x150.webp)

![(Updated) Microsoft Teams: Rule-based enablement of Microsoft 365 third-party apps in the Teams admin center [MC1085133] 4 pexels tirachard kumtanom 112571 347139](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-tirachard-kumtanom-112571-347139-150x150.webp)
![Dynamics 365 Contact Center – Update to provide greater granularity to session rejection reasons [MC1324072] 5 puppet 1636124 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/puppet-1636124_1920-150x150.webp)
![(Updated) PowerPoint for Mac: "Review this presentation" skill in Copilot [MC1309736] 8 (Updated) PowerPoint for Mac: “Review this presentation” skill in Copilot [MC1309736]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-jenna-hamra-248942-804416-150x150.webp)