Microsoft to Block .msix and .msixbundle Attachments in Outlook
- Microsoft is adding .msix and .msixbundle file attachments to its default blocked list in Outlook on the web and the new Outlook for Windows starting in November 2026.
- The change impacts Exchange Online administrators managing OwaMailboxPolicy objects as well as users exchanging installer packages through supported web and desktop applications.
- The upcoming blocks target specific archive and container architectures used to distribute software across different computer configurations.
Microsoft is adding .msix and .msixbundle file attachments to its default blocked list in Outlook on the web and the new Outlook for Windows starting in November 2026. The security update prevents users from sending, receiving, opening, or downloading the modern Windows installation packages through the email clients.
The change impacts Exchange Online administrators managing OwaMailboxPolicy objects as well as users exchanging installer packages through supported web and desktop applications.
Expanding Microsoft Outlook Email Attachment Restrictions
The upcoming blocks target specific archive and container architectures used to distribute software across different computer configurations. MSIX files represent modern Windows installation packages tailored for particular computer architectures, while .msixbundle files act as containers grouping multiple MSIX packages into a single file compatible with various system architectures. Microsoft stated that most organizations will remain unaffected by the policy update because these particular file types see infrequent use in standard email workflows.
The file type restriction forms part of a broader security push by Microsoft to remove and disable legacy Office and Windows features exploited by threat actors in recent campaigns. In June 2025, Outlook began blocking .library-ms and .search-ms file types that had supported phishing and malware attacks against government entities and other organizations since June 2022. Microsoft also altered Outlook for Web and the new Outlook Windows client in October 2025 to stop displaying risky inline SVG images used in malicious exploits.
Microsoft Recommends Pre-Configuring Tenant Policies Before November Rollout
Administrators who do not utilize MSIX or MSIX bundle formats within their tenant do not need to take any action before the security update deploys. For environments where these installation packages remain necessary for daily operations, Microsoft recommends pre-configuring tenant policies.
If your organization relies on these file types, we recommend that you add them to the AllowedFileTypes property of your users’ OwaMailboxPolicy objects prior to rollout.
betanews.com
The rollout schedule begins in early November 2026 for Exchange Online tenants. Microsoft expects the file type additions to reach general availability across all targeted environments by mid-November 2026, automatically enforcing the restrictions on all default and custom OWA Mailbox policies without requiring manual administrator intervention for standard blocking.
