Security2 publishersAlso reported elsewhere2 min readPublished
Microsoft adds MSIX app packages to Outlook's default attachment block from early November
Microsoft will block .msix and .msixbundle attachments by default in Outlook on the web and the new Outlook for Windows from early November. Tenants that still mail app packages need a policy exception before general availability in mid-November.
The Watch · Security desk

What happened
- Microsoft is adding both file types to BlockedFileTypes in the default OWA Mailbox policy and in every custom policy already created in each tenant.
- Once a policy updates, users of the two clients can no longer send, receive, open or download .msix or .msixbundle attachments.
- Outlook began blocking .library-ms and .search-ms files in June 2025, after phishing and malware abuse dating to at least June 2022, including attacks on government entities.
- In October 2025 Microsoft said both clients would stop displaying risky inline SVG images that had been used in attacks.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Tenants that distribute app packages by email must choose before mid-November between an AllowedFileTypes exception and moving that distribution off email.
- exposure Until the rollout reaches a given tenant, a mailed MSIX package still opens in both clients, so attackers keep the attachment route through the November window.
- precedent Three restrictions on these two clients since June 2025 make more default file-type blocks the expected course, and custom policies offer no shelter from them.
The setting sits in OwaMailboxPolicy. "To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy," Microsoft said in a Microsoft 365 message center update [5].
An .msix file is a Windows installation package built for a specific architecture or configuration [2]. An .msixbundle packs several .msix packages into one file that works across architectures [2]. The block closes the attachment route for these packages only in the two clients Microsoft named [1].
Tenants that never use either type need to do nothing, according to Microsoft [7]. Tenants that do use them can add .msix and .msixbundle to the AllowedFileTypes property on their users' OwaMailboxPolicy objects [7]. The block covers both sending and receiving, so an allowance written to a policy reopens both directions for every mailbox assigned to it [13]. How wide the exception runs depends on how many mailboxes share that policy object [13].
"Most organizations are not expected to be affected by this update because these file types are infrequently used," Microsoft said [8]. The company called the change part of "ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments" [9]. The report does not tie the block to a named campaign that delivered MSIX packages by email.
The block on .library-ms and .search-ms came three years after the first recorded abuse of those types [14]. BleepingComputer places this run of changes inside a broader Microsoft effort to disable and remove Office and Windows features that attackers have abused in recent years [10].
What to watch
- A Microsoft 365 message center revision that moves the early-November start or the mid-November general availability date.
- Whether Microsoft extends the MSIX block beyond Outlook on the web and the new Outlook for Windows.
- Whether MSIX lures shift from attachments to download links once the block is live in tenants.