Default compose font: Administrators can allow users to change the default font in Outlook for iOS and Android

🚨 The Signal: Intune administrators can now allow users to override default Outlook mobile compose fonts. Previously, font settings were enforced. This change introduces new configuration keys to grant or deny user flexibility, potentially impacting organizational branding and data loss prevention policies.

The Impact

Intune administrators are affected by new configuration options, with a low security risk related to potential policy non-compliance.

  • Intune administrators: Must review and configure new keys to maintain current policy enforcement.
  • Users: May gain the ability to change fonts if administrators permit it, potentially bypassing branding guidelines.

The Action

  1. Review existing Intune app configuration policies for Outlook for iOS and Android.
  2. Decide whether to allow users to change default font name and/or size.
  3. Configure 'com.microsoft.outlook.Settings.defaultFontName.UserChangeAllowed' key in Intune to 'true' or 'false'.
  4. Configure 'com.microsoft.outlook.Settings.defaultFontSize.UserChangeAllowed' key in Intune to 'true' or 'false'.
  5. Communicate any changes in font policy to end-users.

Domain: Intune · Impact: low · Workload: Exchange Online