Outlook will block .msix and .msixbundle attachments from November
EditorialBy TrustList Editorial
The change covers new Outlook for Windows and Outlook on the web in Exchange Online. Admins who need these Windows package files must add them to AllowedFileTypes before the rollout starts.
- Cybersecurity
- Email Attachment Protection
- Redmond, Wa
About Outlook will block .msix and .msixbundle attachments from November
Outlook will block .msix and .msixbundle attachments from November
5 October 2026: Microsoft is adding .msix and .msixbundle, the Windows app package formats, to the default blocked file types in Outlook on the web and new Outlook for Windows. Users will no longer be able to open or download such attachments in Exchange Online mailboxes. Rollout begins in early November and is expected to finish by mid-November, in worldwide, GCC, GCC High and DoD tenants.
Not yet independently verified. We read the Message Center post through a public archive, not the admin centre. The rollout is described as early to mid-November with no exact days. We will update this when it can be confirmed, and remove this note.
Message Center post MC1488841, published on 5 October, says the two extensions will be added to the BlockedFileTypes list in the default OWA mailbox policy and in every custom policy in a tenant. Microsoft calls the formats infrequently used and expects most organisations to be unaffected. It describes the change as part of its ongoing work to protect organisations from unsafe attachments.
Administrators who do rely on the formats should add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy objects before the rollout begins. Microsoft says no action is needed otherwise. The affected audiences it names are Exchange Online administrators who manage OWA mailbox policies and anyone who sends or receives these attachments in the two clients.
The obvious users to check are software teams and IT departments that mail application packages to testers or branch offices, and vendors that deliver installers as attachments. Classic Outlook is not named in the notice.
The Register notes that Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers used it to distribute malware, and that renaming an attachment or sending a download link can get around the block, so the block does not make a malicious package safe.
Company profile on TrustList: Microsoft
Sources
Categories & features
- Cybersecurity
- Email Attachment Protection
- Redmond, Wa
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.