Microsoft Outlook to block MSIX attachments starting November
Microsoft will block .msix and .msixbundle attachments in Outlook on the web and new Outlook starting November.
Microsoft said Outlook on the web and the new Outlook for Windows will block .msix and .msixbundle attachments by default. The types will be added to BlockedFileTypes in every OWA mailbox policy, with Exchange Online rollout starting in early November and general availability expected by mid-November. Users then cannot send, receive, open, or download them unless administrators add them to AllowedFileTypes. Microsoft said most organizations rarely use the formats and linked the change to earlier blocks of .library-ms, .search-ms, and risky inline SVG images.
- .msix and .msixbundle join the default BlockedFileTypes list in OWA mailbox policies.
- Exchange Online rollout starts early November and should reach general availability by mid-November.
- Users cannot send, receive, open, or download those attachments unless admins allow them.
- Microsoft previously blocked .library-ms, .search-ms, and risky inline SVG images.
Full article450 words · extracted from bleepingcomputer.com · click to collapse

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.
.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.
The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.
After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.
"To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy," Microsoft said in a Microsoft 365 message center update.
"As part of this update, the .msix and .msixbundle file types will be added to the BlockedFileTypes list in the default OWA Mailbox policy and any custom policies created in your tenant."
Admins don't need to take action if .msix or .msixbundle file types aren't used in their organization, but they can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.
"Most organizations are not expected to be affected by this update because these file types are infrequently used," Microsoft added. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments."
This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.
In June 2025, Outlook began blocking .library-ms and .search-ms file types that have been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities.
More recently, in October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were also being used in attacks.
The complete list of attachments that can't be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft's documentation website.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.