Microsoft extends the Outlook naughty step with two more file types
Microsoft will block .msix and .msixbundle attachments in New Outlook for Windows and Outlook on the web.
Microsoft will add .msix and .msixbundle to the default blocked attachment list for New Outlook for Windows and Outlook on the web in Exchange Online. The change, scheduled for early to mid-November 2026, stops users from downloading or opening those Windows application packages unless an administrator allows them. Administrators can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before rollout. Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers abused it to distribute malware.
- Blocked attachment types are Windows packages .msix and .msixbundle.
- The change covers New Outlook for Windows and Outlook on the web.
- Rollout is scheduled for early to mid-November 2026.
- Admins can permit the extensions through OwaMailboxPolicy AllowedFileTypes.
- Microsoft disabled ms-appinstaller by default in December 2023 after malware abuse.
Full article308 words · extracted from theregister.com · click to collapse
software
You didn't really want to be sending around .msix and .msixbundle files, did you?
Microsoft is adding two extra file types to its Outlook block list to strengthen security.
The file types are .msix and .msixbundle, used for Windows application packages and bundles. The change affects New Outlook for Windows and Outlook on the Web in Exchange Online.
By default, users of the affected clients will no longer be able to download or open attachments with these extensions, which is no bad thing because blindly installing a malicious .msix package could compromise a device.
REG AD
That said, although Microsoft noted that the file types were "infrequently used," there are legitimate reasons for their presence in emails. Administrators who need to permit these attachments can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout, scheduled for early to mid-November 2026.
REG AD
"This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," Microsoft said.
The Windows giant's application packaging system has come under fire over the years. Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers abused it to distribute malware. The attachment block adds another layer of protection, unless administrators explicitly allow these file types.
Other file types blocked by Outlook on the Web include .py Python files, .ps1 PowerShell files, and .cab files. It's a little surprising that it has taken until now for .msix and .msixbundle to be added to the list, considering the havoc malicious packages can wreak on a system.
Renaming an attachment's extension or sending a download link may get around the attachment restriction, but neither makes the package safe. Persuading someone to download and install it remains a route for miscreants, even with Windows' other protections in place. ®