Microsoft Outlook to block MSIX attachments starting November
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.
.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.
The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.
After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.
In June 2025, Outlook began blocking .library-ms and .search-ms file types that have been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities .
More recently, in October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were also being used in attacks.
Admins don't need to take action if .msix or .msixbundle file types aren't used in their organization, but they can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.
This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.
The complete list of attachments that can't be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft's documentation website .
Microsoft said in a Microsoft 365 message center update.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
What happened
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.
.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.
The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.
What changed
After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.
In June 2025, Outlook began blocking .library-ms and .search-ms file types that have been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities .
More recently, in October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were also being used in attacks.
Who is affected
Admins don't need to take action if .msix or .msixbundle file types aren't used in their organization, but they can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.
This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.
Why it matters
The complete list of attachments that can't be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft's documentation website .
Response
Microsoft said in a Microsoft 365 message center update.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Attribution
BleepingComputer: Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.