Microsoft is taking another step towards bolstering the security of its Outlook email service by blocking a type of attachment that can be exploited by malicious actors. Starting next month, .msix and .msixbundle attachments will no longer be allowed in Outlook Web and the new Outlook Windows client, as these file types have been abused in recent attacks targeting Microsoft customers.
The change affects organizations using Exchange Online, with the update set to roll out in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies. General availability is expected by mid-November. When implemented, users of Outlook on the web and the new Outlook for Windows will no longer be able to send, receive, open, or download .msix or .msixbundle attachments.
But what are these file types, exactly? In short, they’re modern Windows installation packages tailored for specific computer architectures or configurations. They can also come bundled together as a single file compatible with multiple architectures. Microsoft explains that the decision to block them is part of its ongoing efforts to strengthen security and protect organizations from potentially unsafe file attachments.
It’s worth noting that most organizations won’t be affected by this update, as these file types are relatively infrequently used. However, administrators who do need to allow .msix or .msixbundle attachments can do so by adding them to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects.
This move is part of a broader effort by Microsoft to disable and remove Office and Windows features that have been abused in recent attacks. Just last year, Outlook began blocking certain file types, including .library-ms and .search-ms, which had been exploited in phishing and malware attacks targeting government entities. More recently, Microsoft also announced that it would no longer display risky inline SVG images.
The complete list of attachments that can’t be saved or viewed from Outlook on the web by Exchange Server and Exchange Online users is available on Microsoft’s documentation website for reference. As always, keeping up with the latest security updates and best practices is key to protecting your organization from emerging threats.
For those looking to stay ahead of the curve, it’s essential to familiarize yourself with these types of changes and ensure that your organization’s policies are aligned with the latest security recommendations. By staying informed and proactive, you can better protect your network and prevent potential breaches.
Source: Bleeping Computer — 2026-10-07