Menu Close

Microsoft 365 Reset (2.0.0)

A security-focused update to the MDM-agnostic, unified, user-friendly macOS script to repair, reset, or remove Microsoft 365 components

Background

A December 2023 Microsoft 365 Reset (2.0.0b1) via Jamf Pro Self Service post detailed a “quick-and-dirty Jamf Pro Policy hack for testing Microsoft_Office_Reset_2.0.0.pkg” (which still works as advertised today, more than 1,000 days later).

However, while conducting some internal training, I was pained by how user un-friendly the workflow seemed — even if it did get the job done — which motivated the development of the modern, unified approach that Microsoft-365-Reset.zsh now delivers.

Slideshow

Overview

The latest version is always available in the Microsoft-365-Reset repository on GitHub.com.

The Microsoft-365-Reset.zsh script seeks to provide an MDM-agnostic, unified, user-friendly approach to all of Paul’s Office-Reset goodness.

Additionally, one resolution to the nightmare that is the Adobe Acrobat Add-in Removal for Microsoft 365 is also included.

Under-the-hood

The script consolidates the expanded package workflows into one easy-to-use tool with:

  • Interactive swiftDialog UI in self-service, test, and debug modes
  • Non-interactive execution in silent mode
  • Dependency-aware operation resolution
  • Deterministic execution order
  • Shared logging and exit codes for automation
  • Auto-repair for selected Microsoft apps using Microsoft-hosted packages
  • MOFA community-maintained reset script contents adapted into the unified workflow

This is a potentially destructive script. It runs as root and — depending on the operations selected — it can:

  • Permanently delete local data: Outlook mailbox data, OneNote content that has not synced to the cloud, Office templates and preferences, and sign-in items in the user’s keychain
  • Remove security tooling: remove_defender uninstalls Microsoft Defender
  • Remove every Microsoft 365 app: remove_office also deletes local Outlook profile data, managed preferences, and the shared /Library/Logs/Microsoft folder, which other Microsoft products (for example, Defender and Intune) also write to
  • Force-quit Microsoft apps: unsaved work in Word, Excel, PowerPoint, Outlook, OneNote, OneDrive, and Teams is lost; interactive modes tell the user to save first; silent runs give no warning

There is no undo. Apps can be reinstalled and caches rebuild themselves, but deleted mail, unsynced notes, keychain items, and removed security tooling need separate recovery.

  • test mode is not a dry-run; it performs real operations
  • silent mode shows no dialogs and skips the destructive-action confirmation
  • self-service refuses to run without an explicit --operations / $5 allowlist unless --allow-all-operations / $6 is set

Test in a lab or on a VM — first confirming known-working backups — before broad deployment.

MOFA Parity

The MOFA Community scripts are built upon the original Office-Reset.com tools, ensuring they remain up-to-date, reliable, and continuously improved. 

  • MOFA alignment:
    • Separate reset_license and reset_credentials operations align with MOFA’s separate license-only and broader sign-in reset flows
    • App repair/reinstall flows for Word, Excel, PowerPoint, Outlook, and OneNote stop after repair without continuing into configuration cleanup, matching current MOFA behavior
    • Teams background preservation (destination folders created in the console user’s context), TCC reset, and retention of a valid current Teams app bundle align with current MOFA behavior
    • remove_office removes only the Office-owned children of /Library/Application Support/Microsoft (MAU2.0, MERP2.0, Office365) and no longer forgets the Defender (com.microsoft.wdav) package receipt, matching current MOFA Office Removal; like MOFA, it still removes /Library/Logs/Microsoft and ~/Library/Application Support/Microsoft
  • Intentional divergences from current MOFA behavior:
    • reset_factory directly performs MOFA-aligned suite cleanup and intentionally adds package-era dependency expansion
    • reset_teams suppresses Screen Recording settings in silent mode, preserves classic and work-or-school Teams bundles during a standard reset, does not install current Teams when its main app bundle is absent, and stops before cleanup when Teams backgrounds cannot be archived or staged (backgrounds under a symlinked parent directory are skipped with a WARNING and cleanup continues)
    • AutoUpdate registration treats new Teams as the current TEAMS21 product while keeping classic Teams on the legacy product ID
  • Repo-local operations without current MOFA community-script equivalents:
    • reset_teams_force is a repo-local operation ID that exposes the force-reinstall behavior available through MOFA Teams reset’s INSTALL=force argument; MOFA does not provide a separate force-reset script
    • remove_acrobat_addin remains a repo-local workflow without a current MOFA community-script equivalent

What’s New

2.0.0

⚠️ Breaking Change: ⚠️  

  • self-service mode now exits 10 during preflight when no --operations / $5 allowlist is supplied
    • pass --allow-all-operations or,
    • set Parameter $6 to true for deliberately broad, admin-only policies
  • See CHANGELOG.md for complete details

Support

Best-effort support is available on the Mac Admins Slack (free, registration required) — sans a dedicated channel for this script — or you can open an issue (after reviewing the README.md).

Posted in Microsoft Office, Scripts, swiftDialog, Tips & Tricks

Related Posts

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.