Skip to main content
๐Ÿฆ‰
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
๐Ÿฆ‰
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

ยฉ 2026 M365 Message Center. Created with โค๏ธ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center โ€ข Not affiliated with Microsoft

  1. Home
  2. /
  3. MC871011

Microsoft Outlook for the web: Third-party cookie block causes users to sign in again on Chrome and Edge

Plan for Change
Major Change

Message ID

MC871011
View in Admin Center

Services

Exchange Online
Microsoft 365 for the web

Summary

Outlook for the web's migration to MSAL may cause sign-in prompts due to third-party cookie blocks in Chrome and Edge. Users without device SSO might see a red banner or dialog box requesting re-authentication. Rollout begins late November 2024, with preparations advised for enterprise administrators.

Details

Updated October 9, 2024: We have updated the rollout timeline below. Thank you for your patience.

As communicated in MC711020 Outlook: Outlook for web รขโ‚ฌโ€œ new application ID (January 2024), Microsoft Outlook for the web is undergoing an authentication platform migration to a public client authentication model using MSAL (Microsoft Authentication Library). The change to client-side authentication will be subject to Google's third-party cookie block that may be active in Chrome and Edge.

Google's third-party cookie block impacts navigation to Microsoft Entra ID to perform silent single sign-on (SSO). To overcome this block, Outlook for the web will present a banner for the user to refresh their session. This will enable navigation to Entra ID to refresh their token. SSO-enabled Windows devices are expected to silently sign in users with SSO without requiring further interaction and will not display the banner. This issue affects Outlook for web users. It will not affect users of new Outlook for Windows, Outlook (classic), Outlook for Mac, Outlook Mobile for iOS and Outlook Mobile for Android.

When this will happen:

General Availability (Worldwide): We will begin rolling out late November 2024 (previously late September) and expect to complete by late January 2025 (previously late December).

General Availability (GCC, GCC High, DoD): We will begin rolling out late December 2024 (previously late October) and expect to complete by late February 2024 (previously late December).

How this will affect your organization:

Before this migration: Outlook for the web users were not affected by the third-party cookie block in Chrome and Edge and were able to stay signed in unless they signed out or were signed out due to inactivity.

After Outlook for the web migrates to MSAL, Outlook for the web users without device SSO who are using Google Chrome or Microsoft Edge and who have third-party cookie blocking enabled will start seeing the following if Outlook for the web is not able to silently sign in the user with SSO:

  • Outlook for the web will display a red banner below the ribbon and require users to sign in when a session is open for more than 24 hours.
  • Windowed (deep linked) Mail items and Calendar events will display a blocking dialog requesting users to return to Outlook for the web to sign in when the deep-linked item token expires.
  • Independent of Outlook for the web's migration to MSAL, Outlook for the web may include embedded experiences such as apps that may stop functioning due to the third-party cookie block. If this happens, the app may provide an app-specific experience to refresh their token. Alternatively, the user may be able to right-click the app to launch the app in a browser or can choose to refresh the entire Outlook for the web session.

Sign-in error message in red banner below the ribbon in Outlook for the web: "You need to sign in. Your session has expired. You may need to enable pop-ups in your browser for this site. Sign in to continue":

user notification

Dialog box requesting users to sign in again:

user notification

The authentication rollout will be on by default.

What you need to do to prepare:

  • In Chrome, enterprise administrators can reset the BlockThirdPartyCookies setting to avoid the block.
  • Enterprise administrators can also enable SSO from their Windows devices or add the Microsoft Single Sign On extension for Chrome to ensure their users are not impacted.

This rollout will happen automatically by the specified date with no admin action required before the rollout. You may want to notify your users about this change and update any relevant documentation.

Timeline

๐Ÿ“…
Published
Aug 23, 2024
Message published to Message Center
โœ๏ธ
Updated
Oct 9, 2024
Message content updated
๐Ÿ
End Date
Mar 3, 2025
Message timeline ends

Tags

#Updated message#New feature#User impact#Admin impact

Category

๐Ÿ“‹Plan for Change

Related Messages

Similar updates

MC835643

Microsoft Outlook: Contact deduplication

Jul 25, 2024
MC1009916

New Outlook for Windows and Web: Outlook Newsletters

Feb 19, 2025
MC943640

Microsoft Outlook: Move emails between accounts (new Outlook for Windows and Outlook for the web)

Nov 27, 2024
MC922623โ—

Microsoft new Outlook for Windows and Outlook for the web: Changing how to disable/enable

Oct 31, 2024
MC917748

Microsoft Teams and Microsoft Outlook: Name pronunciation on the profile card

Oct 24, 2024