AI News Feed
Market watch
Cybersecurity

Microsoft to block .msix and .msixbundle email attachments in Outlook

Microsoft will block .msix and .msixbundle email attachments in Outlook on the web and new Outlook for Windows in Exchange Online beginning in November 2026, citing security risks from application package files. Organizations that rely on the formats must allow them before rollout.

Microsoft said it is "updating the default list of blocked file types in OwaMailboxPolicy" to enhance security in Outlook on the web and new Outlook for Windows. The .msix and .msixbundle types will be added to the BlockedFileTypes list in the default OWA Mailbox policy and any custom policies created in a tenant, according to the advisory.

MSIX is a Windows application packaging and installation format, similar to .exe and .msi installers. An .msixbundle can contain multiple .msix packages, such as versions for different processor architectures, so Windows can install the correct one. Both formats are used to distribute Windows applications, including apps delivered through the Microsoft Store.

Microsoft said most organizations are not expected to be affected because the file types are infrequently used. The company described the update as part of ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments. TechRadar noted that sending application packages as email attachments is not a primary way businesses distribute software; managed portals, the Microsoft Store, package management tools, or vendor downloads are more common. That means .msix and .msixbundle files sent by email could often be malicious, TechRadar said.

Exchange Online administrators who manage OWA mailbox policies are affected, as are users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows. Organizations that do not rely on the formats need not take action. Those that do should add the file types to the AllowedFileTypes property of their users' OwaMailboxPolicy objects before the rollout.

Microsoft has added other file types to its blocked list over the years to prevent users from downloading and running malicious attachments from phishing emails. TechRadar, citing The Register, said Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after it was abused to distribute malware. It later blocked .py, .ps1 and .cab files, among others.

Editor's Summary

Microsoft will add .msix and .msixbundle to Outlook's blocked attachment types in Exchange Online in November 2026 to reduce malware delivery through application package files. Organizations that rely on the formats must explicitly allow them before the rollout or lose the ability to download or run them from email. The change continues Microsoft's broad effort to restrict attachment types abused in phishing and malware campaigns.