Microsoft is adding .msix and .msixbundle file types to the default blocked list in Outlook on the Web and the new Outlook for Windows to prevent potential security risks from email attachments.

  • Blocking of .msix and .msixbundle files begins November 2026
  • Change affects New Outlook for Windows and Outlook on the Web users
  • Admins can whitelist these file types if necessary

What happened

Microsoft has announced that starting early November 2026, .msix and .msixbundle file types will be blocked by default as email attachments in New Outlook for Windows and Outlook on the Web within Exchange Online. This update modifies the default OwaMailboxPolicy by adding these formats to its BlockedFileTypes list, preventing users from downloading or sending these files unless explicitly allowed by administrators.

The MSIX format and its bundle variant are modern packaging formats used for installing Windows applications and can contain multiple versions of an app. While designed to improve application installation and update reliability, Microsoft has determined that blocking these files in emails is necessary to mitigate potential security risks from malware distribution.

Why it matters

Although .msix and .msixbundle files are primarily used for legitimate app distribution, they are infrequently sent via email in typical business workflows. Instead, organizations usually deploy software through secure channels like managed portals or the Microsoft Store. The decision to block these file types by default reflects the risk that malicious actors might exploit email to distribute malware disguised as application packages.

This update reinforces Microsoft’s ongoing efforts to safeguard users from unsafe file attachments, following previous blocks on other executable and script-based file types such as .py, .ps1, and .cab. By proactively restricting these potentially weaponizable formats, Microsoft aims to reduce the attack surface for phishing and malware campaigns targeting Exchange Online users.

What to watch next

The rollout will be complete by mid-November 2026, and Exchange Online administrators should review their OWA mailbox policies to determine if these newly blocked file types impact their environments. Organizations that legitimately use .msix or .msixbundle attachments can add these formats to their AllowedFileTypes list to maintain functionality while balancing security considerations.

It will also be important to monitor any feedback or disruptions caused by this change, especially in industries where app packaging and distribution workflows might vary. Microsoft’s continued vigilance in updating its blocked file lists suggests a dynamic approach to combating evolving cyber threats, making communications about security best practices critical for IT teams.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings