GeneralMedium

Microsoft to block MSIX installer attachments in Outlook from November

Outlook on the web and the new Outlook for Windows will block .msix and .msixbundle attachments by default, with rollout to Exchange Online starting in early November.

Microsoft to block MSIX installer attachments in Outlook from November

At a glance

  • Microsoft is adding .msix and .msixbundle to the default blocked attachment list in OWA mailbox policies.
  • Rollout to Exchange Online begins in early November 2026, with completion expected by mid-November.
  • Users will not be able to send, receive, open or download the blocked files.
  • Admins who need the formats can add them to AllowedFileTypes in their OwaMailboxPolicy objects.

Microsoft will start blocking Windows app installer packages in the .msix and .msixbundle formats as email attachments in Outlook on the web and the new Outlook for Windows, BleepingComputer reported on October 7. The change, announced in Microsoft 365 message center update MC1488841, will reach Exchange Online tenants from early November 2026 and is part of a broader effort by the company to remove file types and features that attackers have abused to deliver malware.

What happened

According to BleepingComputer, Microsoft said it is updating the default list of blocked file types to enhance security. The two extensions will be added to the BlockedFileTypes list in all OWA mailbox policies, covering both the default policy and any custom policies in a tenant. Rollout is scheduled to begin in early November, with general availability expected by mid-November 2026.

Once the policies are updated, users of Outlook on the web and the new Outlook for Windows will no longer be able to send, receive, open or download these attachments. Microsoft said most organizations are not expected to be affected because the file types are rarely used.

Technical details

.msix files are modern Windows installation packages built for specific architectures or configurations, while .msixbundle files combine several .msix packages into a single file that works across multiple architectures. Because they install software directly on Windows systems, installer formats like these are attractive to attackers who rely on luring users into opening email attachments.

The BleepingComputer report does not describe specific recent attacks using MSIX email attachments and does not name threat actors. It notes that the move follows earlier hardening steps: in June 2025 Outlook began blocking .library-ms and .search-ms files, which had been exploited in phishing and malware attacks since at least June 2022, including attacks on government entities. In October 2025, Microsoft also stopped Outlook on the web and the new Outlook for Windows from displaying risky inline SVG images that were used in attacks.

Who is affected

The change applies to organizations using Exchange Online with Outlook on the web and the new Outlook for Windows. Organizations that do not exchange MSIX packages by email do not need to take any action, according to Microsoft.

What to do

Administrators whose workflows depend on sending MSIX packages by email can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy objects using Set-OwaMailboxPolicy. Security teams may also want to review whether any internal software distribution processes still rely on email attachments and move them to managed deployment channels, which keeps the new default protection in place for the rest of the organization.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.