Protect.Computer
NEWS

Outlook Will Block MSIX Attachments Starting in November

· 1 min read · Malicious byte
Outlook Will Block MSIX Attachments Starting in November

Microsoft announced that it will add .msix and .msixbundle files to the blocked-attachment list in Outlook on the web and the new Outlook for Windows client. MSIX files are modern Windows installation packages built for specific computer architectures, and an MSIX bundle groups several of them into one file. Once the change lands, these attachments will be blocked by default, and users will no longer be able to send, receive, open, or download them in those clients.

According to BleepingComputer’s report of the Microsoft 365 message center notice, the rollout starts in early November for Exchange Online, where the file types are added to the BlockedFileTypes list in the default OWA mailbox policy and any custom policies, and is expected to reach general availability by mid-November. Microsoft says most organizations should not be affected because the file types are rarely used, and that administrators can allow them by adding them to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects. The change continues Microsoft’s pattern of blocking file types attackers have abused, such as the .library-ms and .search-ms types blocked in June 2025.

How to check if you’re affected

Affected products are Outlook on the web and the new Outlook for Windows connected to Exchange Online. Administrators can check whether anyone in their organization legitimately exchanges MSIX packages by email, and if so, review the AllowedFileTypes and BlockedFileTypes properties of each OwaMailboxPolicy with the Exchange Online PowerShell cmdlets before the November rollout. If nobody sends installers by email, no action is needed. Everyone else should treat any unexpected installer attachment as suspicious and get software from the vendor’s official site instead.

Sources

Related reading