Advisory
Published 2026-10-06
Verified 2026-10-07

Microsoft adds .msix and .msixbundle to the blocked attachment list in new Outlook for Windows and Outlook on the web (Exchange Online), rolling out early to mid-November 2026

Microsoft is adding the Windows app package extensions .msix and .msixbundle to the list of attachment types blocked by default in new Outlook for Windows and Outlook on the web for Exchange Online, The Register reported on 6 October 2026. Once the change lands, users of those clients will no longer be able to download or open attachments with these extensions. Microsoft calls the file types infrequently used and says the change is part of its ongoing work to protect organisations from unsafe attachments. Rollout is scheduled for early to mid-November 2026. Administrators who have a genuine need to receive these packages by email can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before then. Malicious MSIX packages have been used to deliver malware before: Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after it was abused. Primary: The Register (citing Microsoft's announcement).

Product
New Outlook for Windows; Outlook on the web (Exchange Online)
Versions
n/a — default policy change; no CVE
Exploited in Australia?
unknown
Patch to
No action needed for most tenants. If you legitimately email MSIX packages, add .msix and .msixbundle to AllowedFileTypes on the relevant OwaMailboxPolicy before mid-November, or better, move app distribution to Intune or a signed internal store. Keep the ms-appinstaller protocol disabled and block MSIX in mail gateway rules for classic Outlook too.

Primary: The Register — Microsoft extends the Outlook block list with two more file types (6 Oct 2026) · Vendor: Microsoft Learn — Set-OwaMailboxPolicy (AllowedFileTypes / BlockedFileTypes)

tech cloud