Microsoft is adding .msix and .msixbundle files to the blocked attachment list in Outlook on the web and the new Outlook for Windows, with the Exchange Online rollout starting in early November 2026 and finishing by mid-November. After a tenant’s policies update, people in those two clients will be unable to send, receive, open or download either file type.
The company’s notice says the update is meant to “enhance security” and does not spell out which attacks prompted it. The record of what criminals have done with MSIX, the Windows packaging format, is public, though, and it dates back to late 2023, when Microsoft’s own threat analysts documented several criminal groups using MSIX packages and the ms-appinstaller handler to deliver loaders, remote-access tools and, in at least one chain, Black Basta ransomware. The details of those campaigns are below.
MC1488841 and the OwaMailboxPolicy list
The change appears in Microsoft 365 message center item MC1488841, published October 5, 2026 and tagged as a major change with user and admin impact. It covers Worldwide, GCC, GCC High and DoD tenants, and it adds the two extensions to the BlockedFileTypes list in every OWA mailbox policy, custom ones included, not only the default.
The blocked list matters because it overrides the others. Microsoft’s Set-OwaMailboxPolicy reference defines BlockedFileTypes as attachment extensions that “can’t be saved locally or viewed from Outlook on the web,” and states that the block list overrides the allow list and the force-save list. Its default list today already names related Windows packaging types such as .appx and .appref-ms, while .msix does not appear in either the blocked or the allowed defaults.
Administrators who still need the formats have one lever. The notice tells them to add .msix and .msixbundle to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects before the rollout reaches them, and says organizations that never exchange the formats have nothing to do. Microsoft lists no compliance impact. Because the entry was posted on October 5 for a rollout beginning in early November, tenants get roughly a month of warning, which is the sense in which the block arrives “next month.”
The practical effect for a person on the receiving end is blunt. A colleague or vendor who emails a packaged app to someone using Outlook on the web or the new Outlook for Windows will see the file fail to open or download once the tenant policy updates. BleepingComputer’s coverage of the earlier file-type block says affected users can ask administrators to adjust mailbox settings, or share the files inside an archive, under a different extension, or through OneDrive or SharePoint.
Attackers, ms-appinstaller and signed MSIX packages
Microsoft describes MSIX as the modern Windows app packaging format, one that gives an app a clean install and uninstall and automatic updates, and requires every package to be signed before installation. Those same properties made it attractive to criminals who wanted installers that look routine.
In a December 28, 2023 post, Microsoft Threat Intelligence reported that financially motivated groups had been abusing the ms-appinstaller protocol, which hands MSIX packages to Windows, since mid-November of that year. Storm-1113 used search ads imitating Zoom to deliver the EugenLoader malware, and Sangria Tempest used EugenLoader through MSIX packages to drop Carbanak and then Gracewire. Storm-0569 used SEO poisoning with fake Zoom, Tableau, TeamViewer and AnyDesk sites to deliver BATLOADER, and Storm-1674 sent Teams messages with fake SharePoint and OneDrive pages that invoked the installer.
Microsoft’s answer then was to disable the ms-appinstaller protocol handler by default, in App Installer build 1.21.3421.0, after saying the technique could slip past SmartScreen and browser download warnings. It also blocked the malicious Teams tenants it had identified and added an accept-or-block screen for external meeting chats. That response went after the protocol handler and the Teams channel, so an attachment-level block in Outlook is a separate layer, one aimed at the moment a packaged app arrives in a mailbox as a file.
A pattern of trimming the blocked list
The new entries continue a habit of closing file types on a case-by-case basis, each time after a format shows up in real intrusions and each time with the same advice for the few organizations that rely on it. BleepingComputer’s report on the earlier change says Microsoft announced on June 9, 2025 that .library-ms and .search-ms would be blocked from early July 2025, after .library-ms files were used in phishing against government and private targets through CVE-2025-24054 and .search-ms files had been used in attacks since at least June 2022.
The current report adds that the MSIX change shares that logic of removing features attackers have leaned on, and that the notice does not mention classic desktop Outlook. Microsoft’s own forecast for the impact is modest: “Most organizations are not expected to be affected by this update because these file types are infrequently used.”
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Tropical Storm Rachel is dumping up to 12 inches on four Mexican states on its way to major hurricane strength
- The FTC says Lens.com doubled the price shoppers saw in Google ads
- Common allergy, bladder and sleep pills tied to sharply higher dementia odds
- NOAA now gives this winter a 75% chance of the strongest El Nino since 1950