Microsoft Outlook to Block MSIX Attachments Starting November
Policy change aims to disrupt malware and phishing delivery via MSIX packages

Key Takeaways
- Outlook Web and new Outlook for Windows will block .msix and .msixbundle attachments starting November 2026.
- The change targets abuse of the MSIX packaging format used in phishing and malware delivery.
- No patch is required; the adjustment is a policy change in Outlook's attachment filtering.
- It is unknown if legitimate MSIX deployment mechanisms will be affected.
- Exact blocking mechanics and Microsoft's official announcement are pending confirmation.
Quick answers
- What happened?
- Microsoft has announced that starting in November 2026, Outlook Web and the new Outlook for Windows will block .msix and .msixbundle attachments. The move is intended to mitigate abuse of the MSIX packaging format in phishing and malware delivery campaigns, though details on the exact blocking mechanism and impact on legitimate deployments remain pending confirmation.
- Which products are affected?
- Outlook Web, Outlook Windows client
- What should defenders do?
- Users and organizations should review MSIX deployment workflows for potential disruption. Whitelist legitimate MSIX sources if necessary. Monitor official Microsoft security bulletins for the final implementation details and any recommended allowlisting steps.
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. The change is part of ongoing efforts to reduce the attack surface exploited by threat actors who have leveraged MSIX packages in phishing emails and malware distribution. MSIX is a modern Windows app packaging technology, but security researchers have observed it being abused to bypass traditional security controls and execute malicious code. The blocking policy will take effect in November 2026, according to the report. Microsoft has not published a detailed technical specification of the filter, and it is unclear whether legitimate enterprise MSIX deployment workflows will be disrupted. No patch is required, as the change is implemented through Outlook's attachment filtering configuration.
Security Details
MSIX attachments have been used in attacks to deliver malware and execute code; blocking them reduces this attack vector. The change is a policy-based filter in Outlook rather than a software patch.
Affected products
Outlook Web, Outlook Windows client
Mitigation
Users and organizations should review MSIX deployment workflows for potential disruption. Whitelist legitimate MSIX sources if necessary. Monitor official Microsoft security bulletins for the final implementation details and any recommended allowlisting steps.
Sources
BleepingComputer
Microsoft Outlook to block MSIX attachments starting November
Oct 7, 2026 · 15:44
Original link
Related Security News

Acronis Recommends Eight Security Controls for RMM Platforms to Mitigate MSP Risk
Acronis has published guidance identifying eight security controls that Managed Service Providers (MSPs) should evaluate and test when using Remote Monitoring and Management (RMM) software. The recommendations address critical areas including patch management, privileged access controls, incident recovery, and tenant isolation, aiming to reduce the risk of unauthorized access and lateral movement through compromised remote management tools.

Google Suspends Open Source Bug Bounty Program Amid AI-Generated Report Surge
Google has temporarily halted submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a significant increase in AI-generated vulnerability reports. The suspension is intended to manage the influx and protect the program's integrity for legitimate researchers.



