Outlook to block MSIX attachments starting in November

Outlook to block MSIX attachments starting in November

Microsoft will stop Outlook users from exchanging .msix and .msixbundle files as email attachments. Both file types are being added to the blocked list in Outlook on the web (OWA) and the new Outlook for Windows client starting next month.

The company announced the change in a Microsoft 365 message center update. It presents the move as a security measure meant to keep potentially unsafe attachments out of users' inboxes.

What the two file types are

An .msix file is a modern Windows installation package built for a particular computer architecture or configuration. An .msixbundle is a container that packs several .msix packages into one file, so the same download can work across different architectures.

Because both formats exist to install software on Windows machines, they belong to the same family of files that defenders already handle with care when they arrive by email.

Rollout timeline and what changes for users

Exchange Online customers should see the rollout begin in early November, and Microsoft expects general availability by mid-November. During the rollout, both extensions will be added to the BlockedFileTypes list in every OWA Mailbox policy. OwaMailboxPolicy objects are the settings admins use to control what users can do in Outlook on the web.

The update covers the default policy and also any custom policies an organization has created in its tenant.

"To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy," Microsoft said.

Once the policies are updated, the block applies by default. Users of Outlook on the web and the new Outlook for Windows will not be able to send, receive, open or download .msix or .msixbundle attachments.

Options for admins

Organizations that don't use these file types don't need to do anything. Where a business does depend on them, admins can allow the extensions again by adding them to the AllowedFileTypes property of the relevant users' OwaMailboxPolicy objects.

Microsoft expects little disruption. "Most organizations are not expected to be affected by this update because these file types are infrequently used," the company said, adding that the change is "part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments."

Microsoft's documentation website lists every attachment type that Exchange Server and Exchange Online users can't save or view from Outlook on the web.

Part of a longer clean-up

The MSIX block is one step in a broader Microsoft effort to disable or remove Office and Windows features that attackers have abused against its customers in recent years.

In June 2025, Outlook started blocking .library-ms and .search-ms files. Both had been used in phishing and malware attacks since at least June 2022, including campaigns aimed at government entities.

In October 2025, Microsoft said Outlook for Web and the new Outlook for Windows would stop displaying risky inline SVG images, which had also been used in attacks.

Our Take

For most readers, this change will happen quietly. Microsoft says few organizations use MSIX attachments, and the block is applied automatically. Still, admins should check whether any internal teams or software vendors distribute installers this way. If they do, an exception through AllowedFileTypes should be set up before mid-November rather than after users report problems.

The more important point is the pattern. Microsoft is steadily closing email paths that put executable or semi-executable content in front of users. Over the past year that has covered .library-ms, .search-ms, inline SVG images and now MSIX. Each step suggests the company now treats Outlook's attachment filter as a front-line control rather than an afterthought.

Blocking file types only goes so far, though. Attackers who lose one format tend to move to another, such as links to hosted downloads or fake software installers delivered outside email. It is worth watching which formats phishing operators adopt next, whether Microsoft extends similar defaults to classic Outlook, and whether on-premises Exchange Server deployments receive comparable policy updates.