Microsoft Office and Outlook for Mac: MRU and Mailbox Data
Office for Mac keeps recent-file lists in securebookmarks plists and MicrosoftRegistrationDB.reg; Outlook for Mac stores mail in a local profile database.
- Location
- ~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/
- Proves
- Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mail
- Timestamps
- Plist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schema
- Access
- Owning user; Group Containers and Containers need Full Disk Access to collect on current releases
- Retention
- MRU lists hold a limited number of entries; Outlook caches follow account sync settings
- Collection
- UAC, mac_apt, ditto, Disk image
Tools
Compare all tools- mac_aptCLI · open source
- plutilCLI · built into macOS
- sqlite3CLI · built into macOS
What it is
Microsoft 365 apps on macOS are sandboxed App Store-style apps. Each keeps its preferences in its own container, and they share data through the UBF8T346G9.Office group container (the prefix is Microsoft's team ID). Two sources matter most for file access:
- Secure bookmarks: sandboxed apps must keep a security-scoped bookmark for every file the user opened, to reopen it later. Office stores them with a last-used date, which makes a reliable most-recently-used list.
- MicrosoftRegistrationDB.reg: a SQLite database that emulates the Windows registry for Office, with keys, values and last-write times.
Outlook for Mac stores a local copy of mailboxes in its profile folder. Apple Mail is covered separately in Mail.
Where it lives
| Source | Path | Notes |
|---|---|---|
| Secure bookmarks | ~/Library/Containers/com.microsoft.<App>/Data/Library/Preferences/com.microsoft.<App>.securebookmarks.plist | <App> is Word, Excel, Powerpoint |
| App preferences | ~/Library/Containers/com.microsoft.<App>/Data/Library/Preferences/com.microsoft.<App>.plist | Settings, some recent data |
| Office registry | ~/Library/Group Containers/UBF8T346G9.Office/MicrosoftRegistrationDB.reg | May be a symlink to a versioned file |
| Legacy MRU | ~/Library/Preferences/com.microsoft.office.plist | Office 2011-era keys such as 14\File MRU\MSWD; still present on upgraded Macs |
| AutoRecovery | ~/Library/Containers/com.microsoft.<App>/Data/Library/Preferences/AutoRecovery/ | Unsaved or recovered document copies |
| Outlook profile | ~/Library/Group Containers/UBF8T346G9.Office/Outlook/Outlook 15 Profiles/<Profile>/ | Data/Outlook.sqlite, message sources, attachments; newer Outlook versions add other stores |
What it proves
- A document was opened in an Office app from a specific path (local, external volume, network share or cloud folder), and when it was last used.
- The document's creation date and the volume it was on, from the bookmark data.
- The Office user name and initials configured for this account (from legacy keys), which end up in document metadata.
- Unsaved work: AutoRecovery copies can hold content the user never saved.
- Mail sent and received through Outlook, with folders, recipients and attachments, as cached locally.
Key fields
| Source | Field | Meaning |
|---|---|---|
| securebookmarks plist | dictionary key | File URL of the document |
| securebookmarks plist | kBookmarkDataKey | Bookmark blob: path, volume name and UUID, file creation date, user name |
| securebookmarks plist | kLastUsedDateKey | Last use of the document in that app |
| MicrosoftRegistrationDB.reg | HKEY_CURRENT_USER and HKEY_CURRENT_USER_values tables | Key path, value name, type, data |
| MicrosoftRegistrationDB.reg | write_time | Key last-write time |
com.microsoft.office.plist | 14\UserInfo\UserName, 14\File MRU\* | Legacy user info and MRU |
Outlook Outlook.sqlite | Mail, Folders, Mail_OwnedBlocks and related tables | Message metadata; bodies are in separate source files |
The bookmark blob is the same format Finder uses in Recent Items, so the same parsers apply.
Timestamps
kLastUsedDateKey is a plist date (UTC). write_time in MicrosoftRegistrationDB.reg is a Windows FILETIME (100-nanosecond intervals since 1601-01-01 UTC), as decoded by mac_apt. Bookmark creation dates are Mac absolute time. Outlook database date columns vary by version; confirm the epoch against a known message.
Retention
- Secure bookmarks accumulate per app and are pruned by Office; expect dozens to a few hundred entries.
- The registry database persists across Office updates.
- AutoRecovery files are removed when a document is saved or closed normally, and remain after a crash.
- Outlook keeps what the account's sync window allows; Exchange and Microsoft 365 mailboxes can be synced for a limited period only.
Collection
for app in Word Excel Powerpoint; do
sudo ditto "/Users/<user>/Library/Containers/com.microsoft.$app/Data/Library/Preferences" \
"./case/office_<user>/$app"
done
sudo ditto "/Users/<user>/Library/Group Containers/UBF8T346G9.Office" ./case/office_gc_<user>
The group container can be large when Outlook caches mail. UAC collects com.microsoft.office.plist and the securebookmarks plists; mac_apt MSOFFICE parses all three MRU sources.
Parsing
python3 mac_apt.py -o out E01 image.E01 MSOFFICE
plutil -p ./case/office_<user>/Word/com.microsoft.Word.securebookmarks.plist | grep -E 'file://|kLastUsedDateKey'
sqlite3 -readonly MicrosoftRegistrationDB.reg '.tables'
Investigator tips
- Paths under
/Volumes/show documents opened straight from USB drives or mounted images; match volume names with USB devices. - Paths under
~/Library/CloudStorage/link documents to cloud storage clients. - Office documents downloaded from the web keep a quarantine record; macro-enabled files with a quarantine record and an MRU entry reconstruct a phishing chain.
- The dock menu "Open Recent" list in Saved Application State is a second, independent MRU for Office apps.
- Newer Outlook for Mac builds are moving to a different storage engine; if
Outlook.sqliteis small or missing, look for other large files in the profile folder and treat the mailbox server as the authoritative source.