Tech News

Outlook Will Block MSIX and MSIXBundle Attachments Starting in November 2026

Starting in November 2026, Outlook on the web and the new Outlook for Windows will block .msix and .msixbundle attachments by default. Here's what you need to know.

This information was shared by Microsoft in a message center announcement in Microsoft 365 (MC1488841). The Redmond company refers to the list of file types blocked by default in Exchange Online OWA policies (OwaMailboxPolicy). Two extensions are being added: .msix and .msixbundle.

These two formats, not to be confused with .msi, may sound familiar. But if they don't, here's a quick reminder. MSIX is Windows' modern packaging format, used to install applications (an alternative to other formats such as msi and exe). A .msixbundle file, on the other hand, groups multiple MSIX packages into a single file so it can work across multiple architectures. In other words, these are application installers, just like an executable file.

What Changes in Exchange Online in November

The change will be applied automatically to all OWA policies in the tenant, whether it is the default policy or custom policies created by administrators.

  • Timeline: deployment will begin in early November 2026 and should be completed by mid-November 2026. It affects Microsoft 365 tenants worldwide.
  • Affected clients: Outlook on the web and the new Outlook for Windows, connected to Exchange Online.
  • Impact for users: received or sent .msix and .msixbundle attachments will no longer be able to be opened or downloaded from these two Outlook clients.

Microsoft is reassuring: "Most organizations should not be affected by this update because these file types are rarely used." As a matter of fact, I think it's fairly rare to send this type of file by email... If this is a problem for you, you can still add these two extensions to AllowedFileTypes in the relevant OWA policies.

Why the MSIX Format Is Under Scrutiny

If Microsoft has MSIX in its sights, it's because the format has been involved in malicious campaigns multiple times. In February 2022, the Redmond company had already disabled the ms-appinstaller protocol, which allows an application to be installed directly from a web page: it was notably exploited by the Emotet malware, as I explained in this article on disabling MSIX calls for Appx applications.

On December 28, 2023, Microsoft Threat Intelligence reported that since mid-November it had observed several cybercriminal groups (Storm-0569, Storm-1113, Sangria Tempest aka FIN7, and Storm-1674) distributing malicious, signed MSIX packages. Some of these attacks led to the deployment of the Black Basta ransomware.

This time, the email channel is being locked down. However, it is worth noting that Microsoft's announcement does not mention any recent campaign based on MSIX attachments. Instead, Microsoft describes this as part of an ongoing effort to protect organizations from dangerous attachments. So this is more of a preventive measure.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.