Microsoft is adding .msix and .msixbundle file types to the default blocked list in Outlook on the Web and the new Outlook for Windows to prevent potential security risks from email attachments.
- Blocking of .msix and .msixbundle files begins November 2026
- Change affects New Outlook for Windows and Outlook on the Web users
- Admins can whitelist these file types if necessary
What happened
Microsoft has announced that starting early November 2026, .msix and .msixbundle file types will be blocked by default as email attachments in New Outlook for Windows and Outlook on the Web within Exchange Online. This update modifies the default OwaMailboxPolicy by adding these formats to its BlockedFileTypes list, preventing users from downloading or sending these files unless explicitly allowed by administrators.
The MSIX format and its bundle variant are modern packaging formats used for installing Windows applications and can contain multiple versions of an app. While designed to improve application installation and update reliability, Microsoft has determined that blocking these files in emails is necessary to mitigate potential security risks from malware distribution.
Why it matters
Although .msix and .msixbundle files are primarily used for legitimate app distribution, they are infrequently sent via email in typical business workflows. Instead, organizations usually deploy software through secure channels like managed portals or the Microsoft Store. The decision to block these file types by default reflects the risk that malicious actors might exploit email to distribute malware disguised as application packages.
This update reinforces Microsoft’s ongoing efforts to safeguard users from unsafe file attachments, following previous blocks on other executable and script-based file types such as .py, .ps1, and .cab. By proactively restricting these potentially weaponizable formats, Microsoft aims to reduce the attack surface for phishing and malware campaigns targeting Exchange Online users.
What to watch next
The rollout will be complete by mid-November 2026, and Exchange Online administrators should review their OWA mailbox policies to determine if these newly blocked file types impact their environments. Organizations that legitimately use .msix or .msixbundle attachments can add these formats to their AllowedFileTypes list to maintain functionality while balancing security considerations.
It will also be important to monitor any feedback or disruptions caused by this change, especially in industries where app packaging and distribution workflows might vary. Microsoft’s continued vigilance in updating its blocked file lists suggests a dynamic approach to combating evolving cyber threats, making communications about security best practices critical for IT teams.