Microsoft Will Block New File Types in Outlook

The update aims to protect organizations from potentially unsafe file attachments and malware.

Updated on Oct. 7, 2026 in Remote Work

Isometric editorial illustration of matte geometric plates layered over a structured data lattice, representing digital security policy.
Microsoft is restricting .msix and .msixbundle file attachments in New Outlook for Windows and Outlook on the Web starting in November 2026 to improve organizational security. AI Illustration. Upload story photo >

Live Poll

Do you trust companies to decide which file attachments are safe for you to open?

Starting in early November 2026, Microsoft will block .msix and .msixbundle file attachments within New Outlook for Windows and Outlook on the Web. This change updates the default OwaMailboxPolicy to enhance security against malware.

Why it matters

By adding these formats to the restricted list, the company seeks to reduce the risk of malicious code execution through email attachments. Organizations remain capable of overriding these default protections if specific business operations require access to these file types.

Microsoft is adding two file types, .msix and .msixbundle, to the BlockedFileTypes list in OWA Mailbox policies. This update extends existing restrictions that already cover .py, .ps1, and .cab file extensions.

The players

Microsoft

Microsoft is a multinational technology corporation that develops the Windows operating system and the Outlook email platform.

The details

The rollout impacts users of New Outlook for Windows and Outlook on the Web in Exchange Online. Organizations that need to support these files can modify the AllowedFileTypes property of their OwaMailboxPolicy objects to override the new restriction.

Timeline

  1. December 2023: Microsoft previously disabled the ms-appinstaller protocol handler.

  2. Early November 2026: The general rollout of the new file blocking policy will begin.

  3. Mid-November 2026: The rollout is expected to be complete for all users.

Market Landscape

The current restrictions on .msix files follow the 2023 move to disable the ms-appinstaller protocol handler, signaling a persistent shift toward hardening Windows package delivery methods. This strategy forces enterprise IT departments to balance tighter security defaults with custom configuration needs.

Users will no longer be able to open .msix or .msixbundle attachments directly within the specified Outlook applications starting in November. Employees requiring these files for work tasks should consult their IT administrators to ensure appropriate file transfer methods are enabled.

The takeaway

Users should proactively transition to secure file sharing platforms if they rely on these formats for internal document exchange. Regularly reviewing OWA policy configurations helps IT departments maintain productivity while adhering to evolving platform security standards.

Further reading

Learn more about securing enterprise communication environments in our Remote Work section.

Live Poll

Do you trust companies to decide which file attachments are safe for you to open?