Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.
The update, which Microsoft states is part of its ongoing efforts to enhance security, aims to protect organizations from potentially unsafe file attachments. Starting in early to mid-November 2026, users of the affected clients will be prevented from downloading or opening attachments with these extensions by default.
While Microsoft noted that these file types are "infrequently used," legitimate scenarios exist for their transmission via email. Administrators who require the ability to send or receive these attachments can preemptively configure their systems by adding the .msix and .msixbundle extensions to the `AllowedFileTypes` property within the relevant `OwaMailboxPolicy` before the rollout takes effect.
The decision to block these file types follows previous security concerns related to Microsoft's application packaging system. In December 2023, Microsoft disabled the `ms-appinstaller` protocol handler by default after it was exploited by attackers to distribute malware. The current attachment block serves as an additional layer of protection against similar threats.
Other file types already blocked by Outlook on the Web include .py for Python scripts, .ps1 for PowerShell scripts, and .cab files. While the new block enhances security, it is acknowledged that threat actors might attempt to circumvent the restriction by renaming file extensions or providing download links, though such methods do not mitigate the inherent risks of malicious packages. Persuading users to download and install such packages remains a potential vector for compromise, even with existing Windows security features.






