Microsoft Tightens Outlook Security With New MSIX Attachment Block

Microsoft will block MSIX attachments in Outlook starting November 2026. Learn which clients are affected and what administrators should check before rollout.

Oct 8, 2026
3 minute read
Microsoft logo and company name mounted on a brick office building with large windows.

Microsoft wants hackers to have a hard time compromising Outlook users. Image: Simon Ray/Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The next suspicious file in your inbox may not look suspicious at all, and Microsoft is betting that blocking it outright is safer than asking users to judge it.

Microsoft is preparing to block .msix and .msixbundle attachments by default for Exchange Online users of Outlook on the web and new Outlook for Windows, according to a Microsoft 365 message center update cited by BleepingComputer.

MSIX is a legitimate Windows application packaging format, but attackers have abused it to disguise malicious software as normal application installers. Unlike a patch for an Outlook vulnerability, this update tightens attachment restrictions around installer formats that attackers have already abused.

The policy gives organizations another layer of protection against email-based software delivery, while administrators who genuinely rely on MSIX attachments can still allow them through policy.

Details of Microsoft’s new move

MSIX is Microsoft’s format for applications that bundles an app and its required files into a single package that Windows can install and manage, giving developers a simpler way to distribute applications while giving users a more consistent installation experience.

The .msixbundle packages multiple MSIX files together. Instead of distributing separate packages, developers can provide one bundle and let Windows install the version suited to the user's device.

Attackers have abused MSIX packages to distribute malicious software. In other words, the file itself does not mean “malware,” but a maliciously prepared MSIX package can turn a legitimate software-installation process into a delivery mechanism for malicious code.

Microsoft now wants to cut off that delivery route through one of its most popular entry gates — Outlook. 

According to BleepingComputer, rollout will begin in early November 2026 and is expected to finish by mid-November. Microsoft will update both default and custom OWA mailbox policies, preventing affected users from opening or downloading these attachments unless administrators explicitly allow them.

Advertisement

Why is Microsoft making this move?

The change follows Microsoft’s broader efforts to restrict features abused for malware delivery, including earlier moves to block internet-sourced VBA macros and disable the ms-appinstaller protocol.

Microsoft says these restrictions are “part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments.”

Microsoft Threat Intelligence previously documented attackers disguising malicious MSIX packages as legitimate software and distributing them through malicious advertisements and Microsoft Teams phishing. The Outlook change restricts one delivery route; it does not prevent malicious installers from reaching users through websites or other messaging platforms.

Here is what you can do now

Microsoft's change is not a permanent ban on .msix and .msixbundle files. It changes the default attachment policy, meaning the two formats will be blocked by default only.

For enterprises, the bigger question is whether any legitimate business process currently depends on sending MSIX packages through Outlook. If teams distribute internal applications, test builds, or software packages by email, authorized Exchange Online administrators can add .msix and .msixbundle to the AllowedFileTypes property of the relevant OWA mailbox policies before rollout.

That means administrators do not have to accept the new default permanently. They can restore access through their Exchange Online mailbox policies where there is a legitimate need. However, allowing file types blocked by default can increase exposure to security threats.

That means, once the policy change begins rolling out, organizations that need to keep these formats in use must account for them explicitly in their security policies.

Advertisement

For organizations that do not use .msix or .msixbundle attachments, there is nothing specific to change. If they do, the sensible step is to identify the users and workflows that depend on these formats, decide whether email is still the right way to distribute application packages, and make any necessary policy changes before the rollout begins in early November 2026.

Read more: Attachment restrictions are one layer of email defense; learn how attackers also abuse trusted Microsoft services and phishing links to steal session tokens and deliver malware.


Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.