Microsoft Blocks MSIX and MSIXBUNDLE Files in Outlook to Thwart Malware
Microsoft is enhancing Outlook's security by blocking .msix and .msixbundle file types in its New Outlook for Windows and Outlook on the Web clients to prevent the distribution of malicious application packages.

Microsoft is bolstering the security of its Outlook email client by adding two new file types to its default block list: .msix and .msixbundle. These extensions are commonly used for packaging and distributing Windows applications. The change, which affects users of the New Outlook for Windows and Outlook on the Web within Exchange Online, aims to prevent attackers from using these legitimate application packaging formats to deliver malware.
Starting in early to mid-November 2026, users of the affected Outlook clients will be unable to download or open email attachments bearing these extensions. This proactive measure is designed to mitigate the risk of users inadvertently installing malicious software disguised as legitimate application installers. Microsoft has stated that this update is part of their ongoing commitment to enhancing security and protecting organizations from potentially unsafe file attachments.
The decision to block .msix and .msixbundle files comes after previous instances where similar packaging mechanisms were abused. Notably, Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 due to its exploitation by attackers for malware distribution. While Microsoft acknowledges that these file types are "infrequently used," they recognize that legitimate use cases exist.
For organizations that rely on these file types for legitimate business purposes, administrators have the option to re-enable them. This can be achieved by adding the .msix and .msixbundle extensions to the AllowedFileTypes property within the relevant OwaMailboxPolicy settings. However, Microsoft advises caution when doing so, given the potential for abuse.
This move aligns with Outlook's existing security measures, which already block a range of potentially dangerous file types. Previously blocked extensions include .py for Python files, .ps1 for PowerShell scripts, and .cab archive files. The inclusion of .msix and .msixbundle further strengthens the perimeter against executable content delivered via email attachments.
Despite these blocking mechanisms, attackers may still attempt to circumvent restrictions. Techniques such as renaming attachment extensions or providing download links to malicious packages could be employed. Furthermore, even with Windows' built-in protections, social engineering tactics aimed at persuading users to download and install such packages remain a viable attack vector for threat actors.
The addition of .msix and .msixbundle to Outlook's blocked file types underscores the evolving threat landscape and Microsoft's continuous efforts to adapt its security posture. By restricting these potentially risky file types by default, Microsoft aims to reduce the attack surface and protect its users from a growing array of sophisticated threats.