Skip to main content
CybersecurityVulnerability Management

Microsoft Outlook to Block MSIX Attachments in Security Push

Person working at desk with laptop and scattered papers, MSIX file on desk.

"To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy," Microsoft said in a Microsoft 365 message center update.

Microsoft's change: .msix and .msixbundle added to BlockedFileTypes

Microsoft will add the .msix and .msixbundle file types to the list of blocked attachments in Outlook on the web (OWA) and the new Outlook for Windows. According to the company, .msix files are modern Windows installation packages tailored for specific computer architectures or configurations, and .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures. Once the update is applied, those file types will be added to the BlockedFileTypes list in the default OwaMailboxPolicy and in any custom OwaMailboxPolicy objects in tenants.

Exchange Online rollout: early November start, mid-November general availability

Microsoft will begin rolling the change out to Exchange Online users in early November and expects it to reach general availability by mid-November. After the OwaMailboxPolicy objects are updated, .msix and .msixbundle attachments will be blocked by default in affected clients.

Outlook on the web and new Outlook for Windows: immediate user effects

When the policies take effect, users of Outlook on the web and the new Outlook for Windows will no longer be able to send, receive, open, or download .msix or .msixbundle attachments. Microsoft stated the update is "to enhance security in Outlook on the web and new Outlook for Windows," and that Outlook clients will enforce the blocking through the updated OwaMailboxPolicy settings.

Admins: how to respond and the whitelist option

  • Microsoft said administrators do not need to take action if .msix or .msixbundle file types are not used in their organizations.
  • If an organization requires these file types, admins can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects.
  • Microsoft noted that "most organizations are not expected to be affected by this update because these file types are infrequently used."

Context: prior Outlook blocks and a broader removal of abused features

Microsoft framed the change as part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers. The company previously took related measures: in June 2025 Outlook began blocking .library-ms and .search-ms file types that had been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities. In October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were being used in attacks. Microsoft publishes the complete list of attachments that can't be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users on its documentation website.

How admins, end users, and security teams will react

  • Admins: those already not using .msix/.msixbundle can take no action; those with operational need must modify the AllowedFileTypes property on OwaMailboxPolicy objects to permit the formats.
  • End users: users of Outlook on the web and the new Outlook for Windows should expect these file types to be blocked by default and unavailable for sending, receiving, opening, or downloading once the policy update arrives.
  • Security teams: this change is one more step in Microsoft's sequence of mitigations removing file types and features that have been weaponized in attacks; teams tracking exploited attachment vectors will see this as part of an ongoing hardening effort.

For administrators and security teams preparing for the early-November rollout, Microsoft’s documentation holds the current, authoritative list of blocked attachments and the OwaMailboxPolicy settings that will be updated. The company’s message makes clear the default posture will be blocking these package formats unless explicitly allowed.

Source: BleepingComputer — Microsoft Outlook to block MSIX attachments starting November