Microsoft Outlook to block .msix and .msixbundle attachments starting November

Security update targets Windows installer file types abused in attacks

By LineZotpaper
Published
Read Time2 min
Microsoft will add .msix and .msixbundle file types to the list of blocked attachments in Outlook on the web and the new Outlook for Windows client, beginning in early November and reaching general availability by mid-November, as part of ongoing efforts to protect customers from malicious file attachments.

Microsoft has announced that it will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows client starting next month. The changes will roll out to Exchange Online users in early November and are expected to be fully available by mid-November.

.msix files are modern Windows installation packages designed for specific computer architectures or configurations, while .msixbundle containers group multiple .msix packages into a single file compatible with multiple architectures.

After the policy update, users will no longer be able to send, receive, open, or download these attachment types by default in the affected Outlook clients. Administrators can whitelist the file types by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.

"Most organizations are not expected to be affected by this update because these file types are infrequently used," Microsoft said in a Microsoft 365 message center update. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments."

The move follows previous Outlook security changes, including blocking .library-ms and .search-ms file types in June 2025, and stopping the display of inline SVG images in October 2025, both of which were being exploited in phishing and malware attacks targeting government and other entities.

§

Analysis

Why This Matters

  • The blocking of .msix and .msixbundle attachments directly reduces a potential attack vector that threat actors have exploited through other Windows file types.
  • Organizations that legitimately use these installer formats for software distribution may face workflow disruptions, requiring administrative whitelisting.
  • This is part of a broader pattern of Microsoft tightening attachment security after years of malicious abuse of Office and Windows features.

Background

Microsoft has been progressively locking down Outlook attachment handling in response to real-world attacks. .msix files are modern Windows installer packages, and .msixbundle files are containers supporting multiple architectures. While infrequently used in business settings, they have the potential to deliver harmful payloads if abused. The move aligns with a wider trend: in June 2025, Outlook blocked .library-ms and .search-ms files after they were used in attacks since 2022; in October 2025, inline SVG images were also blocked due to exploitation.

Key Perspectives

Microsoft: The company frames the change as a security enhancement, noting that most organizations will be unaffected and that the file types are rarely used. IT Administrators: Organizations that rely on .msix packages for internal software distribution will need to update Outlook mailbox policies to allow the attachment types, adding an administrative step. End Users: General users will experience no change in daily workflow unless they attempt to send or receive these file types, which are uncommon for most business correspondence.

What to Watch

  • The rollout to Exchange Online in early November and whether any compatibility issues arise for administrators.
  • Potential for threat actors to shift to other less-common attachment types that remain unblocked.
  • Future Outlook security updates as Microsoft continues to review and disable features that can be weaponized in attacks.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.