Microsoft announced that it will add .msix and .msixbundle files to the list of blocked attachments in Outlook Web and the new Outlook Windows client. This change will prevent users from sending, receiving, opening, or downloading these file types by default.
The update will begin rolling out to Exchange Online users in early November. The new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies, with general availability expected by mid-November.
Microsoft stated this update is to enhance security in Outlook on the web and the new Outlook for Windows. It is part of a broader initiative to disable features that attackers have exploited in past attacks against Microsoft customers. Most organizations are not expected to be affected as these file types are infrequently used.
Admins do not need to take action if their organization does not use .msix or .msixbundle files. However, if these file types are required, admins can whitelist them by adding them to the AllowedFileTypes property of their users' OwaMailboxPolicy objects.
This move follows previous security updates, including the blocking of .library-ms and .search-ms file types in June 2025, which were exploited in phishing and malware attacks. In October 2025, Microsoft also stopped displaying risky inline SVG images in Outlook for Web and the new Outlook Windows client due to their use in attacks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft will block .msix and .msixbundle attachments in Outlook Web and the new Outlook Windows client starting in November. This change is part of Microsoft's ongoing security efforts to prevent the abuse of file types in attacks.