> ## Documentation Index
> Fetch the complete documentation index at: https://resources.athenaintel.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Athena for Microsoft 365: Deploy the Excel, Word and PowerPoint Add-in

> Everything your IT team and users need to use Athena inside Excel, Word and PowerPoint: requirements, admin deployment from the Microsoft 365 admin center, the manifest option for tenants that block the Office Store, network allowlist, security details and user setup.

**Athena for Microsoft 365** brings Athena into a task pane in Excel, Word and PowerPoint. Users can chat with Athena about the document they have open, insert results directly into it, and let Athena make edits after they approve them. Conversations started in Office can be picked up again in Athena on the web.

Most organizations install the add-in once, centrally, through the **Microsoft 365 admin center**. This page covers the steps for IT administrators and for end users.

<Card title="Get Athena for Microsoft 365" icon="microsoft" href="https://marketplace.microsoft.com/en-us/product/WA200012417">
  Install the add-in directly from Microsoft Marketplace. If your organization blocks Office Store add-ins, ask your IT administrator to [deploy it for you](#for-it-administrators-deploy-the-add-in).
</Card>

<Info>Questions or problems? Email [support@athenaintel.com](mailto:support@athenaintel.com) or contact your Athena account team. We're happy to join a short call while your admin deploys.</Info>

## At a glance

| | |
| - | - |
| **Add-in name** | Athena for Microsoft 365 (publisher: Athena Intelligence) |
| **Marketplace listing** | [Athena for Microsoft 365](https://marketplace.microsoft.com/en-us/product/WA200012417) (asset ID `WA200012417`) |
| **Add-in ID** | `7c1f5f3a-2e9b-4b7d-9d3e-0a6f4c9b21e5` |
| **Manifest URL** | `https://d2brvcn8zlw890.cloudfront.net/manifests/athena-office.manifest.xml` |
| **Office apps** | Excel, Word, PowerPoint |
| **Platforms** | Windows, Mac and Office on the web |
| **Office permission** | `ReadWriteDocument`, limited to the document the user has open |
| **Microsoft Graph / Entra consent** | None required |
| **Sign-in** | The user's existing Athena account, including your Athena SSO |

## Before you start

* **Athena accounts.** Every user who will use the add-in needs an Athena account. If your organization uses [SSO for Athena](/docs/getting-started/sso), users sign in to the add-in the same way.
* **Microsoft 365 licenses.** Users need Microsoft 365 Business, Office 365 / Microsoft 365 Enterprise (E1, E3, E5 or F3) or an equivalent plan, with an Exchange Online mailbox.
* **Office versions.** Microsoft 365 Apps on Windows (version 1704 or later), Office for Mac (version 15.34 or later), or Office on the web. Admin-deployed add-ins are not available on iPad.
* **Admin role.** The person deploying needs one of the **Global Administrator**, **Exchange Administrator** or **AI Administrator** roles in the Microsoft 365 admin center.
* **A pilot group.** We recommend starting with a group of 10–25 users. Use a top-level Microsoft 365 group or mail-enabled security group. Nested groups and non-mail-enabled security groups are not supported for add-in assignment.

## Why can't users install it themselves?

Many organizations turn off **"Let users access the Office Store"** in the Microsoft 365 admin center. When that setting is off, a user who opens the listing sees a message such as:

> *Microsoft 365 has been configured to prevent individual acquisition and execution of Office Store add-ins.*

This is expected, and Athena is working normally. It means an administrator must deploy the add-in for those users with one of the options below. Users don't need to do anything else until it is deployed.

## For IT administrators: deploy the add-in

Choose one option. **Option 1** is recommended because Microsoft keeps the add-in up to date automatically. Use **Option 2** if your organization blocks the Office Store and the add-in is not available, or doesn't appear for users, after Option 1.

<Tabs>
  <Tab title="Option 1: Deploy from the Microsoft Store">
    <Warning>Deploy to **Just me** first, then widen access. If you choose **Everyone** or a group during the first deployment, some tenants fail with "The requested action failed." Deploying to yourself and then changing access avoids this.</Warning>

    <Steps>
      <Step title="Open Integrated apps">
        Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com) and go to **Settings → Integrated apps**.
      </Step>

      <Step title="Start an add-in deployment">
        Select **Add-ins** at the top of the page, then **Deploy Add-In**.

        <Frame>
          <img width="300" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/01-add-ins-deploy.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=20cc7b3b02939318bf2f0561b5670d8d" alt="Add-ins page in the Microsoft 365 admin center with the Deploy Add-In button" data-path="images/microsoft-365-add-in/01-add-ins-deploy.png" />
        </Frame>

        On **Deploy a new add-in**, select **Choose from the Store**.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/02-deploy-new-add-in.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=cdc0e9819e431433cf8c40a069861e6f" alt="Deploy a new add-in dialog with Choose from the Store and Upload custom apps" data-path="images/microsoft-365-add-in/02-deploy-new-add-in.png" />
        </Frame>

        <Tip>Use **Add-ins → Deploy Add-In** rather than **Get apps**. Some tenants see "We are unable to initiate the deployment" from the **Get apps** route.</Tip>
      </Step>

      <Step title="Find Athena">
        Search for **Athena** and select **Add** next to **Athena for Microsoft 365**.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/03-search-store.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=586c0cb16481bf12288fb464b94345e2" alt="Select add-in dialog showing Athena for Microsoft 365 in the Store search results" data-path="images/microsoft-365-add-in/03-search-store.png" />
        </Frame>

        The details page lists the version, the supported apps and the permissions. Select **Add** and accept the terms when prompted.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/04-add-in-details.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=cbf881d6d6971ecb12e73861215a6cbb" alt="Athena for Microsoft 365 details page with the Add button and permissions" data-path="images/microsoft-365-add-in/04-add-in-details.png" />
        </Frame>
      </Step>

      <Step title="Assign it to yourself">
        On **Configure add-in**, choose **Just me**, then continue and select **Deploy**.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/05-assign-just-me.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=ba7b32dce527e6618ef1c93e035ddc06" alt="Configure add-in dialog with Just me selected under Assign Users" data-path="images/microsoft-365-add-in/05-assign-just-me.png" />
        </Frame>
      </Step>

      <Step title="Wait for the deployment">
        The admin center shows **Getting your add-in ready**. This can take a few minutes.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/06-getting-ready.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=49fb72461cccfee621f2917ad66e21c0" alt="Deploy dialog showing Getting your add-in ready" data-path="images/microsoft-365-add-in/06-getting-ready.png" />
        </Frame>

        When it shows **Your add-in has been deployed**, you can open Excel, Word or PowerPoint from the buttons to check that Athena is on the ribbon. Select **Next**.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/07-deployed.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=bfa0f3ef85422b5d240a3158ad1c103c" alt="Deploy dialog confirming Your add-in has been deployed, with buttons to open Word, PowerPoint and Excel" data-path="images/microsoft-365-add-in/07-deployed.png" />
        </Frame>
      </Step>

      <Step title="Give your users access">
        Select **Change who has access to add-in**.

        <Frame>
          <img width="600" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/08-change-access.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=c1e6d41ee04c9381aa2b957b59fd104a" alt="Deploy dialog with the Change who has access to add-in link" data-path="images/microsoft-365-add-in/08-change-access.png" />
        </Frame>

        Under **Assign Users**, choose **Specific users / groups** and select your pilot group, or choose **Everyone**. Leave **Status** on, then select **Save**.

        <Frame>
          <img width="450" src="https://mintcdn.com/athenaintelligence-e46bc9d3/MB1Tby12aHoscCtF/images/microsoft-365-add-in/09-edit-everyone.png?fit=max&auto=format&n=MB1Tby12aHoscCtF&q=85&s=f75e46605c173d75963aa32439d741ee" alt="Edit Athena for Microsoft 365 dialog with Assign Users options, Status toggle and Save button" data-path="images/microsoft-365-add-in/09-edit-everyone.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>

  <Tab title="Option 2: Upload the manifest (Office Store blocked)">
    <Steps>
      <Step title="Open Integrated apps">
        Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com) and go to **Settings → Integrated apps**.
      </Step>

      <Step title="Upload a custom app">
        Select **Upload custom apps**, then choose **Office Add-in** as the app type.
      </Step>

      <Step title="Provide the manifest">
        Choose **Provide link to manifest file** and paste:

        ```
        https://d2brvcn8zlw890.cloudfront.net/manifests/athena-office.manifest.xml
        ```

        Or download that file and choose **Upload manifest file (.xml) from device**. Select **Validate**, then **Next**.
      </Step>

      <Step title="Assign it to yourself">
        Under **Assign Users**, choose **Just me**.
      </Step>

      <Step title="Deploy">
        Review and select **Deploy**. Wait until the admin center shows **Your add-in has been deployed**, then select **Next**.
      </Step>

      <Step title="Give your users access">
        Select **Change who has access to add-in**, add your pilot group or choose **Everyone**, then select **Save**, as in Option 1.
      </Step>
    </Steps>

    <Tip>Want Athena to open automatically when users open a file exported from Athena with live sync? Ask [support@athenaintel.com](mailto:support@athenaintel.com) for the **admin-managed manifest**. It is the same add-in, but it is set up to open the Athena pane automatically on those files. Upload it with the same steps instead of the link above. The link above works for everything else, and users can always open Athena from the **Home** ribbon.</Tip>

    <Note>With this option, product updates to the task pane reach users automatically. If Athena publishes a new manifest version, for example to support another Office app, we will let your admin know so they can upload it again.</Note>
  </Tab>
</Tabs>

### How long until users see it?

Microsoft says deployment can take **up to 24 hours** to reach every user. Some clients take longer before the button appears on the ribbon. Users should close and reopen Office after the deployment.

### Check the deployment

1. Ask one pilot user to open Excel, Word or PowerPoint and go to **Home → Add-ins** (or **Insert → Add-ins → My Add-ins**), then open the **Admin Managed** tab.
2. Confirm **Athena for Microsoft 365** is listed and opens.
3. Have them sign in and send a test message (see [For users](#for-users-get-started) below).

### Expand to more users

When the pilot is working, go to **Settings → Integrated apps → Add-ins**, select **Athena for Microsoft 365**, and under **Assign Users** add more groups or choose **Everyone**. Select **Save**.

## Network and firewall allowlist

If your organization uses a proxy, firewall, SSL inspection or a secure web gateway, allow the following hosts over HTTPS (port 443). Secure WebSocket (`wss://`) traffic must be allowed to the hosts marked below. Chat responses stream over WebSockets.

| Host | Used for |
| - | - |
| `d2brvcn8zlw890.cloudfront.net` | The add-in's task pane and manifest |
| `appsforoffice.microsoft.com` | Microsoft's Office JavaScript library, which the task pane needs to start |
| `app.athenaintel.com` | Sign-in and links to Athena on the web |
| `auth.athenaintel.com` | Athena account authentication |
| `api.athenaintel.com` | Athena API, and voice input (**WebSocket**) |
| `iris.prd.athenaintel.com` | Chat streaming (**WebSocket**) |
| `keryx.prd.athenaintel.com` | Live document sync (**WebSocket**) |

If your organization signs in to Athena through SSO, your identity provider's sign-in pages must also be reachable from Office.

## Security and data

* **Document access is limited to the open file.** The add-in requests the Office `ReadWriteDocument` permission only. It cannot read the user's mailbox, OneDrive or other files, and it does not request Microsoft Graph or Entra ID consent.
* **Users control what is shared.** A chip above the message box identifies the document context (for example, the current selection) that will be sent with the next message. It shows a summary, not a full preview of the contents. Turning it off stops sharing document context with chat and turns off Athena's document tools. Live sync runs separately: if a document is live-synced with Athena, turning off the chip does not stop edits from syncing. Use **Stop** or **Unlink** in the live-sync panel to stop it.
* **Edits need approval.** Athena asks before it changes the open document. **Allow** approves edits for the rest of that conversation, **Decline** rejects them, and **Allow for 8 hours in this document** skips later prompts for that one document for eight hours. Approval never carries over to other documents. Users can also insert results themselves with **Insert**.
* **Sign-in uses your Athena account.** Users sign in through an Office sign-in window with their Athena credentials or SSO. Sessions use short-lived access tokens, and signing out of the add-in revokes the session.
* **Your Athena security controls apply.** Conversations are stored in your Athena workspace under the same policies as the rest of Athena, and Athena never trains models on customer data. See [Security and Data Handling](/docs/getting-started/security-and-data-handling) for compliance details, or email [team@athenaintel.com](mailto:team@athenaintel.com) for compliance documentation.

## For users: get started

<Steps>
  <Step title="Open the add-in">
    In Excel, Word or PowerPoint, go to **Home → Add-ins**, open the **Admin Managed** tab, and select **Athena for Microsoft 365**. After the first launch, Athena appears on the **Home** ribbon.
    <Tip>Don't see it? Your IT team may still be deploying it. Close and reopen Office, and allow up to 24 hours after IT confirms the deployment.</Tip>
  </Step>

  <Step title="Sign in">
    Select **Sign in** in the task pane and sign in with your Athena account in the window that opens. If your organization uses SSO, you'll be taken to your usual company sign-in.
  </Step>

  <Step title="Ask Athena about your document">
    Select some cells, text or a slide, and ask a question. The chip above the message box identifies the context shared with chat. Turn it off to stop sharing that context and turn off document tools. Turning off the chip does not stop live sync: if the document is live-synced with Athena, use **Stop** or **Unlink** in the live-sync panel.
  </Step>

  <Step title="Put the results to work">
    Use **Insert** to place an answer in your document, or ask Athena to make the change and approve it when prompted.
  </Step>
</Steps>

### Things to try

| App | Try asking |
| - | - |
| Excel | "Explain how this model calculates EBITDA." · "Build a summary table of sales by region from this sheet." · "Add a chart of the selected range." |
| Word | "Tighten this section and keep the key points." · "Turn these notes into an executive summary." · "Check this draft against our brand guidelines." |
| PowerPoint | "Rewrite this slide for an executive audience." · "Suggest a title and three bullets for this slide." · "Summarize this deck in one paragraph." |

## Troubleshooting

<AccordionGroup>
  <Accordion title="Users see 'configured to prevent individual acquisition…'">
    Your organization blocks self-service installs from the Office Store. An administrator must deploy the add-in using [Option 1 or Option 2](#for-it-administrators-deploy-the-add-in). This is expected and is not an error in Athena.
  </Accordion>

  <Accordion title="The add-in was deployed but users can't see it">
    * Allow up to 24 hours, and have users fully close and reopen Office.
    * Look under **Home → Add-ins → Admin Managed**, not the Store tab.
    * Confirm the user is a direct member of the assigned group. Nested groups are not supported.
    * If your tenant blocks the Office Store and you used Option 1, deploy with **Option 2** instead.
    * An Exchange admin can run `Get-OrganizationConfig | fl AppsForOfficeEnabled` in Exchange Online PowerShell. If it returns `False`, add-ins are disabled for the organization.
  </Accordion>

  <Accordion title="Deployment shows 'The requested action failed'">
    This generic admin center error usually has one of these causes:

    * The first deployment was assigned to **Everyone** or a group. Deploy to **Just me** first, then use **Change who has access to add-in** to widen access (see [Option 1](#for-it-administrators-deploy-the-add-in)).
    * The admin role was activated through Privileged Identity Management (see below). Deploy from an account with Global Administrator or Exchange Administrator permanently assigned.
    * The deployment was started from **Get apps**. Start again from **Settings → Integrated apps → Add-ins → Deploy Add-in**.
    * The Store deployment is blocked by tenant policy. Use [Option 2](#for-it-administrators-deploy-the-add-in) to upload the manifest instead.
  </Accordion>

  <Accordion title="Deployment fails for an admin whose role is activated through PIM">
    The Integrated apps page doesn't recognize admin roles activated through Microsoft Entra Privileged Identity Management. Deploy from an account where the required role is permanently assigned.
  </Accordion>

  <Accordion title="'We are unable to initiate the deployment' from Get apps">
    Use **Settings → Integrated apps → Add-ins → Deploy Add-in** instead of **Get apps**.
  </Accordion>

  <Accordion title="The sign-in window is blank or closes immediately">
    Check that `app.athenaintel.com`, `auth.athenaintel.com` and your SSO provider's sign-in pages are reachable and not blocked by your proxy. Then try again from the task pane.
  </Accordion>

  <Accordion title="Messages send but responses never arrive">
    Your network is likely blocking WebSocket traffic. Allow `wss://` connections to `iris.prd.athenaintel.com` (see [Network and firewall allowlist](#network-and-firewall-allowlist)), and exclude it from SSL inspection if your gateway interrupts WebSockets.
  </Accordion>

  <Accordion title="The task pane is blank on Windows">
    Office on Windows displays add-ins with Microsoft Edge WebView2. Make sure the WebView2 runtime is installed. If your organization uses Windows Information Protection, add `msedgewebview2.exe` to its list of protected apps.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.