DKDKCISSPSearch
Threat Research

Microsoft Outlook to block MSIX attachments starting November

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.

DKCISSP News DeskBleepingComputer7 Oct 2026, 9:14 pm
Microsoft Outlook to block MSIX attachments starting November
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.

.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.

The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.

After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.

In June 2025, Outlook began blocking .library-ms and .search-ms file types that have been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities .

More recently, in October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were also being used in attacks.

Admins don't need to take action if .msix or .msixbundle file types aren't used in their organization, but they can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.

This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.

The complete list of attachments that can't be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft's documentation website .

Microsoft said in a Microsoft 365 message center update.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

What happened

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.

.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.

The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.

What changed

After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.

In June 2025, Outlook began blocking .library-ms and .search-ms file types that have been exploited in phishing and malware attacks since at least June 2022, including attacks targeting government entities .

More recently, in October 2025, Microsoft also announced that Outlook for Web and the new Outlook Windows client would no longer display risky inline SVG images that were also being used in attacks.

Who is affected

Admins don't need to take action if .msix or .msixbundle file types aren't used in their organization, but they can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.

This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.

Why it matters

The complete list of attachments that can't be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft's documentation website .

Response

Microsoft said in a Microsoft 365 message center update.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Attribution

BleepingComputer: Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN THREAT RESEARCH

More cybersecurity reporting

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceThe Hacker News · 7 Oct 2026, 8:28 pmHalf of Cybersecurity Pros Still Rely on Passwords Despite Security CoInfosecurity Magazine · 7 Oct 2026, 3:45 pmLinux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and TaiwanThe Hacker News · 6 Oct 2026, 11:54 pmIncident affecting ASOS customersNCSC-UK · 6 Oct 2026, 10:18 pm