Microsoft has announced that it will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows client starting next month. The changes will roll out to Exchange Online users in early November and are expected to be fully available by mid-November.
.msix files are modern Windows installation packages designed for specific computer architectures or configurations, while .msixbundle containers group multiple .msix packages into a single file compatible with multiple architectures.
After the policy update, users will no longer be able to send, receive, open, or download these attachment types by default in the affected Outlook clients. Administrators can whitelist the file types by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.
"Most organizations are not expected to be affected by this update because these file types are infrequently used," Microsoft said in a Microsoft 365 message center update. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments."
The move follows previous Outlook security changes, including blocking .library-ms and .search-ms file types in June 2025, and stopping the display of inline SVG images in October 2025, both of which were being exploited in phishing and malware attacks targeting government and other entities.