Security News

Outlook to Block Two More Windows App Package File Types by Default

The Register · 7 Oct 2026
Key Takeaway Check whether your business has any genuine need to email .msix or .msixbundle files before November 2026, and if not, leave the block in place and remind staff not to install software from unexpected emails or links.

Microsoft is adding two more file types to the list of attachments that Outlook will not let users download or open. The extensions are .msix and .msixbundle, which are used for Windows application packages and bundles. The change applies to New Outlook for Windows and Outlook on the Web in Exchange Online, and is scheduled for early to mid-November 2026. Microsoft described the move as part of ongoing efforts to help protect organisations from potentially unsafe attachments.

The reasoning is straightforward: blindly installing a malicious .msix package could compromise a device. Microsoft's application packaging system has been criticised before. In December 2023, the company disabled the ms-appinstaller protocol handler by default after attackers abused it to distribute malware. Outlook on the Web already blocks other file types, including .py Python files, .ps1 PowerShell files and .cab files.

Microsoft noted the file types are infrequently used, but there can be legitimate reasons to email them. Administrators who need to allow them can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout. The block is not a complete fix: renaming an attachment's extension or sending a download link may get around it, and persuading someone to download and install a package remains a route for attackers.

Outlook Microsoft Email Security Malware Exchange Online

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.