Skip to content
TrustList
News

Outlook will block .msix and .msixbundle attachments from November

Editorial

By TrustList Editorial

The change covers new Outlook for Windows and Outlook on the web in Exchange Online. Admins who need these Windows package files must add them to AllowedFileTypes before the rollout starts.

About Outlook will block .msix and .msixbundle attachments from November

Outlook will block .msix and .msixbundle attachments from November

5 October 2026: Microsoft is adding .msix and .msixbundle, the Windows app package formats, to the default blocked file types in Outlook on the web and new Outlook for Windows. Users will no longer be able to open or download such attachments in Exchange Online mailboxes. Rollout begins in early November and is expected to finish by mid-November, in worldwide, GCC, GCC High and DoD tenants.

Not yet independently verified. We read the Message Center post through a public archive, not the admin centre. The rollout is described as early to mid-November with no exact days. We will update this when it can be confirmed, and remove this note.

Message Center post MC1488841, published on 5 October, says the two extensions will be added to the BlockedFileTypes list in the default OWA mailbox policy and in every custom policy in a tenant. Microsoft calls the formats infrequently used and expects most organisations to be unaffected. It describes the change as part of its ongoing work to protect organisations from unsafe attachments.

Administrators who do rely on the formats should add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy objects before the rollout begins. Microsoft says no action is needed otherwise. The affected audiences it names are Exchange Online administrators who manage OWA mailbox policies and anyone who sends or receives these attachments in the two clients.

The obvious users to check are software teams and IT departments that mail application packages to testers or branch offices, and vendors that deliver installers as attachments. Classic Outlook is not named in the notice.

The Register notes that Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers used it to distribute malware, and that renaming an attachment or sending a download link can get around the block, so the block does not make a malicious package safe.

Company profile on TrustList: Microsoft

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy