
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.
.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.
The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.
After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.
“To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy,” Microsoft said in a Microsoft 365 message center update.
“As part of this update, the .msix and .msixbundle file types will be added to the BlockedFileTypes list in the default OWA Mailbox policy and any custom policies created in your tenant.”
Admins don’t need to take action if .msix or .msixbundle file types aren’t used in their organization, but they can whitelist them by adding them to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects if needed.
“Most organizations are not expected to be affected by this update because these file types are infrequently used,” Microsoft added. “This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments.”
This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.
In June 2025, Outlook began blocking .library-ms and .search-ms file types that have been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities.
More recently, in October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were also being used in attacks.
The complete list of attachments that can’t be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft’s documentation website.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
