Outlook Adds Two More Blocked File Types
Microsoft will block .msix and .msixbundle attachments in New Outlook for Windows and Outlook on the Web starting in November 2026.
Microsoft is widening the list of file types it refuses to let through Outlook, adding two packaging formats that can carry executable code straight into a user's inbox. The change targets .msix and .msixbundle, the extensions used for Windows application packages and their bundles, and it applies to New Outlook for Windows and Outlook on the Web in Exchange Online.
Under the default configuration, users of those clients will no longer be able to download or open attachments bearing those extensions. The restriction is not confined to a single platform — it follows the mailbox policy for organizations running Exchange Online.
The ban starts in November
Microsoft has scheduled the rollout for early to mid-November 2026, according to the company. Administrators who want to preserve the ability to send and receive these attachments have a window before then to adjust their settings.
The mechanism for that adjustment is the AllowedFileTypes property of the relevant OwaMailboxPolicy. Adding the two extensions to that property lets an organization opt out of the block for its mailboxes.
Microsoft framed the move as an incremental tightening rather than a response to a specific incident. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," the company said.
Why msix packages are risky
The two formats are not obscure to Windows administrators, but they are unusual in email traffic. Microsoft described them as "infrequently used" in the context of attachments, which is part of why they had not previously been singled out.
The security case for blocking them rests on what happens when a recipient opens one. A .msix package is an installer. A user who downloads and runs a malicious package can compromise the device it lands on, since the package is designed to be trusted by the operating system as a legitimate application delivery mechanism.
That risk is not hypothetical for this class of file. Microsoft's application packaging system has drawn scrutiny over the years, and in December 2023 the company disabled the ms-appinstaller protocol handler by default after attackers abused it to distribute malware.
What was already blocked
The new entries join a list of extensions that Outlook on the Web already refuses. Among them are .py Python files, .ps1 PowerShell files, and .cab files — formats that, like the msix family, can be used to deliver or execute code rather than simply display content.
Microsoft's handling of those formats set the pattern for this week's addition: a default deny, with an administrative escape hatch for organizations that have a documented need. The difference is timing. The source coverage notes it is somewhat surprising that .msix and .msixbundle took until now to join the list, given the damage a malicious package can do once installed.
Blocking attachments is not the whole story
The attachment restriction closes one delivery path, but it does not make the underlying package format safe. An attacker who cannot attach a .msix file can rename the extension or send a link that points to a download elsewhere.
Neither workaround defeats the block at the mail gateway — a renamed file may still be inspected or rejected, and a link is not an attachment at all. But both routes still depend on persuading a person to download and install the package.
That social engineering step is where the remaining risk sits. Windows has other protections in place, and the source material notes that these do not eliminate the danger of a user choosing to run an untrusted installer.
What administrators should check
For organizations running New Outlook for Windows or Outlook on the Web through Exchange Online, the practical question is whether any legitimate workflow depends on .msix or .msixbundle attachments. Microsoft's own description characterizes such use as uncommon, which suggests most tenants will not need to act.
Where a business process does rely on these formats, the fix is to add the extensions to the AllowedFileTypes property on the applicable OwaMailboxPolicy. That change needs to happen before the rollout window opens in early to mid-November 2026.
Administrators who take no action will inherit the default block. Users in the affected clients will find that attachments with these extensions cannot be downloaded or opened, and the failure will look like a mail client restriction rather than a server-side policy change.
The timeline behind the change
The relevant dates are few but specific. The block is scheduled for early to mid-November 2026. The earlier action on the ms-appinstaller protocol handler came in December 2023.
- Early to mid-November 2026 — rollout of the .msix and .msixbundle attachment block for New Outlook for Windows and Outlook on the Web in Exchange Online
- December 2023 — Microsoft disables the ms-appinstaller protocol handler by default after abuse by attackers distributing malware
- Pre-rollout — window for administrators to add the two extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy
Microsoft's statement places the update in the context of broader attachment policy rather than a single threat. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," the company said.
Why the gap matters
The addition of two more extensions is a small configuration change with a narrow blast radius: tenants that never see .msix attachments in their mail flow will notice nothing. But the fact that these formats were absent from the block list until now is itself the interesting part, because the packaging system they belong to has a documented history of abuse.
That history is why the December 2023 decision on the ms-appinstaller protocol handler stands as the closest prior example in the source material. The pattern Microsoft is following — disable by default, allow by explicit administrative configuration — is the same one now applied to the msix family.
What this means for the reader
If you administer Exchange Online mailboxes, the actionable item is a configuration review rather than an emergency response. Check whether any team depends on .msix or .msixbundle attachments, and if so, decide before early to mid-November 2026 whether to allow them through the OwaMailboxPolicy. If you take no action, the default block applies.
For users, the change is mostly invisible until it isn't — a message that used to arrive with an installable package will now be stripped of its attachment or refused outright. That inconvenience is the intended trade-off, since a package a user cannot open is a package an attacker cannot talk them into running.
For the wider picture, the block closes one route without closing the category. Renamed extensions and download links remain available to anyone trying to deliver a malicious package, and the final step still depends on a person deciding to install it. The restriction raises the effort required to reach that moment; it does not remove the moment itself.
Sources
- The Register Original source
Continue Reading
Pwn2Own Ireland Day One Yields 32 Zero-Days
Researchers exploited 32 zero-days at Pwn2Own Ireland 2026, targeting phones, printers, smart home hubs and AI infrastructure for $388,500.
Red Hat Batch-Fixes 400 Open-Source Flaws
Red Hat's Lightwell Clearinghouse exits pilot after remediating over 400 novel vulnerabilities in foundational Java libraries since June.
September M&A: 39 Deals Reshape Security
Cybersecurity M&A stayed busy in September 2026 with 39 announced deals, spanning OT security, AI governance and offensive testing.