
Microsoft is rolling out one of Exchange Online's most-requested features this month: the ability to recall a sent email at a recipient in a different Microsoft 365 tenant. How does it work, what do IT administrators need to configure, and which scenarios does it actually help with?
It has happened to most of us: an email sent to an external contact with the wrong attachment, the wrong version of a document, or simply the wrong recipient. Within your own Microsoft 365 environment, you have been able to recall such a message for some time via the built-in recall function in Exchange Online. But the moment the recipient was in a different Microsoft 365 tenant, that action was pointless: the button was there, the recall was initiated, but the message simply stayed in the external recipient's inbox. That changes now. Microsoft is currently rolling out one of Exchange Online's most-requested features: cross-tenant message recall.
Exchange Online has offered users the ability to recall a sent email for years. The recall works by replacing the original message with an empty version or deleting it entirely from the recipient's inbox, provided the message has not yet been opened. Within the same Microsoft 365 environment this runs smoothly: Exchange has the authority to write to all mailboxes in that tenant.
The problem was that the vast majority of business email goes to external recipients. An employee sending a document to a customer in another tenant, a manager sending a confidential attachment to the wrong person outside the organisation, a sales employee sharing a draft proposal with a partner before it is finalised. In all those cases Exchange Online was powerless: to modify or delete messages in an external mailbox, an explicit trust relationship had to exist. That was missing.
The new functionality uses an allow-list model. The receiving organisation has the final say: it decides which external Microsoft 365 tenants are permitted to recall emails for their users. By default the feature is disabled; no one can affect your mailboxes without your IT administrator explicitly granting permission.
The process works as follows. Organisation A sends an email to Organisation B. An employee of A realises the message was wrong and initiates a recall via Outlook. Exchange Online checks whether the tenant of Organisation A is on Organisation B's allow list. If it is, the recall is processed: the message disappears from the recipient's inbox as long as it has not yet been opened. If A's tenant is not on the list, the recall fails. The sender sees this in the recall status report that Outlook generates automatically.
Identification uses Entra tenant IDs. Every Microsoft 365 environment has a unique tenant ID, similar to a registration number for organisations in the Microsoft ecosystem. That ID acts as the key in the trust relationship.
The receiving organisation must take two steps: enable the feature at tenant level and add the desired external tenants to the allow list. The setting applies to all mailboxes in the environment; there is no granular control per user or per mailbox at this point.
This is a deliberate architectural choice. Organisations that do not want to offer the feature need do nothing. The default setting is disabled and passive: without active configuration by your administrator, no external party can do anything with your mailboxes. That is an important governance aspect for organisations in regulated sectors or with strict information management requirements.
Configuration is done via Exchange Online PowerShell. You need the Exchange Online Management module and administrator rights in your tenant. First connect via Connect-ExchangeOnline.
Then enable the feature with the command Set-CrossTenantRecallConfiguration -CrossTenantRecallEnabled $true. This opens the capability, but without any trusted external tenants yet.
Next, add the tenant ID of the external organisation to the allow list: Set-CrossTenantRecallConfiguration -AllowedSenderTenantIds @{Add="xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"}. The tenant ID of an organisation can be obtained from their IT administrator or via the Microsoft Entra portal. To add multiple tenants, place the IDs comma-separated in the same call.
Check the current configuration with Get-CrossTenantRecallConfiguration. This shows which tenants are on the allow list and whether the feature is active. Remove a tenant with Set-CrossTenantRecallConfiguration -AllowedSenderTenantIds @{Remove="xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"}.
Cross-tenant recall has the same limitation as internal recall: the message must still be unread. If the recipient has already opened the email, nothing is deleted. The sender sees this per recipient in the recall status report.
Other situations in which the recall fails: the receiving organisation has not enabled the feature, the sender's tenant ID is not on the allow list, or the recipient does not use Exchange Online. On-premises Exchange environments and other mail providers are not supported. Recalls can also fail when email is processed via an external connector or a shared mailbox with non-standard configuration.
Cross-tenant recall adds the most value for organisations that collaborate structurally with fixed external partners and trust each other enough to set up the allow list. Think of an accounting firm working for a defined set of regular clients, a legal team that regularly consults with external lawyers at a partner firm, or IT service providers who communicate daily with their client organisations.
For one-off or occasional contacts, the feature adds less. You will not add a tenant ID for every external contact you have, nor do you need to. The feature is designed for trusted, structural relationships.
A practical recommendation: discuss the capability proactively with your regular partner organisations. If both sides configure the allow list, all employees benefit from the recall option in both directions. That is a concrete argument for taking the initiative with your established external relationships.
Cross-tenant message recall is currently rolling out in phases to all Microsoft 365 tenants worldwide, including GCC, GCC High, and DoD environments. Expected completion is mid-September 2026. No additional licences are required: the feature is included in Exchange Online as part of standard Microsoft 365 subscriptions.
Whether you want to activate the feature and which external parties you want to trust is a deliberate choice that fits your IT policy and your business relationships. Want support configuring Exchange Online governance, rolling out cross-tenant features, or drafting policy around email management? Contact Zarioh for a no-obligation conversation.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Microsoft 365

Microsoft 365

Microsoft 365