Microsoft Outlook to block MSIX attachments in November
Microsoft is expanding its default list of blocked file types in Outlook Web and the new Outlook Windows client to enhance user security.

Upcoming Changes to Outlook Security
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. According to details shared by <a href="https://www.bleepingcomputer.com/author/sergiu-gatlan/">Sergiu Gatlan</a>, this update forms part of ongoing platform security improvements.
The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, and is expected to reach general availability by mid-November.
Understanding MSIX Files and the Block
.msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single file compatible with multiple computer architectures.
After the policies are updated, .msix or .msixbundle attachments will be blocked by default, and users of Outlook on the web and new Outlook for Windows will no longer be able to send, receive, open, or download them.
As <a href="https://admin.microsoft.com/#/MessageCenter/:/messages/MC1488841">Microsoft said</a> in a Microsoft 365 message center update, "To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy."
Administrator Options and Tenant Impact
Administrators do not need to take action if .msix or .msixbundle file types are not used in their organization. However, they can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects if needed.
Further configuration guidance can be reviewed directly on <a href="https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/set-owamailboxpolicy?view=exchange-ps#-blockedfiletypes">Microsoft's documentation website</a> for enterprise environments.
Most organizations are not expected to be affected by this update because these file types are infrequently used. This update is part of ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments.
Broader Security Measures in Outlook
This move is part of a broader effort to disable and remove Office and Windows features that attackers have abused in attacks targeting Microsoft customers in recent years.
Earlier security adjustments saw Outlook implement restrictions such as those detailed when Outlook <a href="https://www.bleepingcomputer.com/news/security/microsoft-outlook-to-block-more-risky-attachments-used-in-attacks/">began blocking .library-ms and .search-ms file types</a> to mitigate exploitation vectors.
Additional protective measures have continuously rolled out across Outlook Web and the new Outlook Windows client to minimize risks from various file formats and display vectors.
Sources
- BleepingComputerMicrosoft Outlook to block MSIX attachments starting November
Continue chronologically



