Block MSIX attachments in Outlook, what small orgs need to know
Microsoft will add .msix and .msixbundle to Outlook's blocked attachments for Exchange Online users starting in early November, affecting Outlook on the web and the new Outlook for Windows.
Microsoft will add .msix and .msixbundle files to the default blocked attachment list for Outlook on the web and the new Outlook for Windows for Exchange Online tenants, with a rollout starting in early November and general availability expected by mid-November, according to BleepingComputer. After Microsoft updates mailbox policies, users will not be able to send, receive, open, or download those attachments by default.
What Microsoft is changing and why
The files being blocked are Windows installer formats: .msix is an installation package tailored to particular architectures or configurations, and .msixbundle groups multiple .msix packages for compatibility across architectures. BleepingComputer reports Microsoft is adding those file types to the BlockedFileTypes list in OWA Mailbox policies.
BleepingComputer notes this change is part of a broader effort by Microsoft to remove or disable Office and Windows features attackers have abused. Past actions include blocking .library-ms and .search-ms files in June 2025 and blocking risky inline SVG images in October 2025.
How this will affect your users and mail flow
Once the policy update reaches your tenant, anyone using Outlook on the web or the new Outlook for Windows will find .msix and .msixbundle attachments blocked by default. That means those attachments cannot be sent, received, opened, or downloaded from the web client or the new Windows client until an admin changes policy settings. BleepingComputer reports admins do not need to act if their organization does not use these file types.
Microsoft also told BleepingComputer: "Most organizations are not expected to be affected by this update because these file types are infrequently used." This change applies specifically to Exchange Online mailbox policies controlling OWA behavior.
block MSIX attachments: immediate steps for small orgs and nonprofits
If you rely on these installer files or accept them from partners, make a short plan now. Suggested actions:
- Inventory current use: check whether anyone in your organization sends or receives .msix or .msixbundle files and which business processes depend on them.
- Communicate to staff: tell people that these attachments will be blocked in Outlook on the web and the new Outlook for Windows so they do not assume an email with an installer should arrive the same way.
- Decide on alternatives: if installers are needed, agree on a supported transfer method (for example an approved file share or signed package distribution) rather than emailing installer bundles.
- If you must allow the types, have an admin whitelist them: add the file types to the AllowedFileTypes property on users' OwaMailboxPolicy objects, per Microsoft guidance reported by BleepingComputer. Only do this if you have a clear business need and compensating controls.
- Check mailbox policies and test: before changing production policies, test allowing the types for a small group so you understand the user experience and any security tradeoffs.
- Review the full blocked-attachment list on Microsoft's documentation site to confirm other types you rely on are not affected, as BleepingComputer advises.
If you want a quick external check of how exposed your site is, consider starting with a free external scan: Want to know how exposed your own site is? Start with a free external scan.
Who needs to act and what to watch for
According to BleepingComputer, most organizations likely will not need to change anything because .msix and .msixbundle are not widely used. If your IT team or vendors deploy MSIX installers directly via email, you need to plan for the block and pick an alternative distribution method or whitelist the types.
Admins should watch their Exchange Online and OWA Mailbox policy settings as the change rolls out. The update will add the types to the BlockedFileTypes list in default OWA Mailbox policies and in any custom policies present in a tenant, per the Microsoft update cited by BleepingComputer.
What to expect next
Microsoft's rollout timing is early November for the initial update and mid-November for general availability, according to the report. Expect tenant policy changes to appear in your Exchange Online environment during that window. If you manage mail policies, watch Microsoft 365 admin messages and your OWA mailbox policies so you can confirm when the change reaches your tenant and take action only if you need to allow the file types.
For the authoritative details and context, see the original report on BleepingComputer.
Sources
- Microsoft Outlook to block MSIX attachments starting November BleepingComputer
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.