Microsoft is taking steps to strengthen security in its popular Outlook email client by blocking two types of attachments that have been exploited by attackers. Starting next month, users will no longer be able to send, receive, open, or download files with the .msix and .msixbundle extensions.
These file types are used for modern Windows installation packages, tailored for specific computer architectures or configurations, and their bundled counterparts. While they may seem like innocuous attachments, Microsoft has deemed them a security risk due to their potential use in attacks targeting its customers. This move is part of the company’s ongoing efforts to disable and remove features that have been abused by attackers.
The change will begin rolling out to Exchange Online users in early November, when the new file types will be added to the BlockedFileTypes list in all OWA Mailbox policies. General availability is expected by mid-November. After the update, any attempts to send or receive .msix or .msixbundle attachments will result in a blocked message.
Microsoft emphasizes that most organizations won’t be affected by this change since these file types are infrequently used. However, administrators can still whitelist them if needed by adding them to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects. This update is part of Microsoft’s broader effort to enhance security in its products and protect its customers from potential threats.
This move follows a similar decision made earlier this year when Microsoft began blocking .library-ms and .search-ms file types due to their exploitation in phishing and malware attacks since at least June 2022. More recently, Outlook also stopped displaying inline SVG images that were being used by attackers. The complete list of attachments that can’t be saved or viewed from Outlook on the web is available on Microsoft’s documentation website.
For users, this change means a slight reduction in functionality but a significant boost to security. While it may not be immediately noticeable for most, administrators should review their organization’s attachment policies and whitelist any necessary file types if needed. This move serves as a reminder that software vendors are constantly working to strengthen security features and protect their customers from emerging threats.
In practice, this means users can still attach files with other extensions but will encounter issues when trying to send or receive .msix or .msixbundle attachments. Administrators should review Microsoft’s documentation on whitelisting file types if they require these specific attachments for business operations. This update is a significant step in the ongoing battle against malicious actors, and it’s essential for users to stay informed about security updates to protect themselves from potential threats.
Source: Bleeping Computer — 2026-10-07