Security in Microsoft 365

As an employee, you need to ensure that you store and manage your information in the right way.

Do not store sensitive personal data or data covered by secrecy in Microsoft 365

It is prohibited to store sensitive personal data and data covered by secrecy. 

This means that you cannot store information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, as well as personal data relating to health or sexual life, genetic or biometric data. Information about health can be, for example, sick leave, pregnancy and doctor's visits.

Can I store personal data?

In Microsoft 365, you may store personal data that does not violate confidentiality or sensitive personal data according to the information in the question above.

Where can I store material of high protection value?

For the storage of files with a high protection value, the university offers Skyddade dokument (secure storage space).

Read more about secure storage space

Add-ins are not allowed in Microsoft 365

It is not possible to integrate add-ins in Microsoft 365.

What is an add-in?

It's an application you add to get additional functionality in the original product, in this case Microsoft 365.

For example, it could be using the Grammarly tool (add-in) for correct spelling (functionality) in Word (original product in M365).

Why are add-ins not allowed in Microsoft 365?

Umeå University must ensure that the applications and software used are approved from a security, technical, contractual and legal perspective. This means that there must be a contract and that personal data processor agreements, risk and vulnerability analysis, information classification and impact analysis must be completed for the applications to be used.

These add-ins applications have not gone through any university review process and may therefore pose a security risk. By removing these applications, we reduce the risk of you as a user unintentionally exposing information to unauthorized persons.

Are there any exceptions?

Yes, the EndNote, Mendeley, and Zotero add-in software will continue to be available in Microsoft 365.

We have looked at and evaluated the add-in applications that are most used at the university and come to the conclusion that during a transition period we approve the three additions for reference management as we can see that need for them is big.

How do I access the add-in?

Endnote and Zotero are installed and used just as before.

Learn more about reference management software

For access to Mendeley, you need to contact ITS through the Service Desk.

What if I want to use a different add-in?

At this time, we will not accept any add-in Microsoft 365 than the three mentioned above.

We are working on a process for managing add-in requests. More information will come.

Elin Sköld
10/31/2022