Skip to Content

MC1488841 Update to default blocked file types in OwaMailboxPolicy

Summary

  • Exchange Online will add .msix and .msixbundle to the default blocked file types in OwaMailboxPolicy for Outlook on the web and new Outlook for Windows.
  • The same block will also be applied to any custom OWA mailbox policies in the tenant.
  • Users will no longer be able to open or download .msix or .msixbundle attachments in those Outlook experiences.
  • If your organization depends on these file types, update the relevant OwaMailboxPolicy objects to allow them before rollout.

Primary Service: Exchange
Admin Impact: Medium
User Impact: Medium
Release Start: 01 Nov 2026
Release End: 15 Nov 2026
Services: Exchange, Outlook
Category: Plan for change
Tags: Admin Action, Feature Update, User Adoption

History

10/5/2026 Item Added to Message Center

Microsoft Message

To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy. As part of this update, the .msix and .msixbundle file types will be added to the BlockedFileTypes list in the default OWA Mailbox policy and any custom policies created in your tenant. Most organizations are not expected to be affected by this update because these file types are infrequently used. This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments.

Rollout schedule

General Availability (Worldwide, GCC, GCC High, DoD): Rollout begins in early November 2026 and is expected to complete by mid-November 2026.

Impact on your organization

Who is affected

  • Exchange Online administrators who manage OWA mailbox policies
  • Users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows

Platforms and services

  • Outlook for the web
  • New Outlook for Windows
  • Exchange Online

What will happen

The .msix and .msixbundle file types will be added to the BlockedFileTypes list in all OWA Mailbox policies in your organization, including the default policy and any custom policies created in your tenant.
Users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows will no longer be able to open or download them.

Action required and recommendations

No action is required if your organization does not rely on the .msix or .msixbundle file types. If your organization relies on these file types, we recommend that you add them to the AllowedFileTypes property of your users’ OwaMailboxPolicy objects prior to rollout.

Learn more

  • Blocked attachments in Outlook | Microsoft Support
  • Set-OwaMailboxPolicy -AllowedFileTypes | Microsoft Learn
  • Set-OwaMailboxPolicy -BlockedFileTypes | Microsoft Learn

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.