A security-focused update to the MDM-agnostic, unified, user-friendly macOS script to repair, reset, or remove Microsoft 365 components

Background
A December 2023 Microsoft 365 Reset (2.0.0b1) via Jamf Pro Self Service post detailed a “quick-and-dirty Jamf Pro Policy hack for testing Microsoft_Office_Reset_2.0.0.pkg” (which still works as advertised today, more than 1,000 days later).
However, while conducting some internal training, I was pained by how user un-friendly the workflow seemed — even if it did get the job done — which motivated the development of the modern, unified approach that Microsoft-365-Reset.zsh now delivers.
Slideshow
Overview
The latest version is always available in the Microsoft-365-Reset repository on GitHub.com.
The Microsoft-365-Reset.zsh script seeks to provide an MDM-agnostic, unified, user-friendly approach to all of Paul’s Office-Reset goodness.
Additionally, one resolution to the nightmare that is the Adobe Acrobat Add-in Removal for Microsoft 365 is also included.
Under-the-hood
The script consolidates the expanded package workflows into one easy-to-use tool with:
- Interactive swiftDialog UI in
self-service,test, anddebugmodes - Non-interactive execution in
silentmode - Dependency-aware operation resolution
- Deterministic execution order
- Shared logging and exit codes for automation
- Auto-repair for selected Microsoft apps using Microsoft-hosted packages
- MOFA community-maintained reset script contents adapted into the unified workflow
Caution
This is a potentially destructive script. It runs as root and — depending on the operations selected — it can:
- Permanently delete local data: Outlook mailbox data, OneNote content that has not synced to the cloud, Office templates and preferences, and sign-in items in the user’s keychain
- Remove security tooling:
remove_defenderuninstalls Microsoft Defender - Remove every Microsoft 365 app:
remove_officealso deletes local Outlook profile data, managed preferences, and the shared/Library/Logs/Microsoftfolder, which other Microsoft products (for example, Defender and Intune) also write to - Force-quit Microsoft apps: unsaved work in Word, Excel, PowerPoint, Outlook, OneNote, OneDrive, and Teams is lost; interactive modes tell the user to save first;
silentruns give no warning
There is no undo. Apps can be reinstalled and caches rebuild themselves, but deleted mail, unsynced notes, keychain items, and removed security tooling need separate recovery.
testmode is not a dry-run; it performs real operationssilentmode shows no dialogs and skips the destructive-action confirmationself-servicerefuses to run without an explicit--operations/$5allowlist unless--allow-all-operations/$6is set
Test in a lab or on a VM — first confirming known-working backups — before broad deployment.
MOFA Parity
The MOFA Community scripts are built upon the original
Office-Reset.comtools, ensuring they remain up-to-date, reliable, and continuously improved.
- MOFA alignment:
- Separate
reset_licenseandreset_credentialsoperations align with MOFA’s separate license-only and broader sign-in reset flows - App repair/reinstall flows for Word, Excel, PowerPoint, Outlook, and OneNote stop after repair without continuing into configuration cleanup, matching current MOFA behavior
- Teams background preservation (destination folders created in the console user’s context), TCC reset, and retention of a valid current Teams app bundle align with current MOFA behavior
remove_officeremoves only the Office-owned children of/Library/Application Support/Microsoft(MAU2.0,MERP2.0,Office365) and no longer forgets the Defender (com.microsoft.wdav) package receipt, matching current MOFA Office Removal; like MOFA, it still removes/Library/Logs/Microsoftand~/Library/Application Support/Microsoft
- Separate
- Intentional divergences from current MOFA behavior:
reset_factorydirectly performs MOFA-aligned suite cleanup and intentionally adds package-era dependency expansionreset_teamssuppresses Screen Recording settings insilentmode, preserves classic and work-or-school Teams bundles during a standard reset, does not install current Teams when its main app bundle is absent, and stops before cleanup when Teams backgrounds cannot be archived or staged (backgrounds under a symlinked parent directory are skipped with aWARNINGand cleanup continues)- AutoUpdate registration treats new Teams as the current
TEAMS21product while keeping classic Teams on the legacy product ID
- Repo-local operations without current MOFA community-script equivalents:
reset_teams_forceis a repo-local operation ID that exposes the force-reinstall behavior available through MOFA Teams reset’sINSTALL=forceargument; MOFA does not provide a separate force-reset scriptremove_acrobat_addinremains a repo-local workflow without a current MOFA community-script equivalent
What’s New
2.0.0
⚠️ Breaking Change: ⚠️
self-servicemode now exits10during preflight when no--operations/$5allowlist is supplied- pass
--allow-all-operationsor, - set Parameter
$6totruefor deliberately broad, admin-only policies
- pass
- See CHANGELOG.md for complete details
Support
Best-effort support is available on the Mac Admins Slack (free, registration required) — sans a dedicated channel for this script — or you can open an issue (after reviewing the README.md).








