Summary
- Exchange Online will add .msix and .msixbundle to the default blocked file types in OwaMailboxPolicy for Outlook on the web and new Outlook for Windows.
- The same block will also be applied to any custom OWA mailbox policies in the tenant.
- Users will no longer be able to open or download .msix or .msixbundle attachments in those Outlook experiences.
- If your organization depends on these file types, update the relevant OwaMailboxPolicy objects to allow them before rollout.
Primary Service: Exchange
Admin Impact: Medium
User Impact: Medium
Release Start: 01 Nov 2026
Release End: 15 Nov 2026
Services: Exchange, Outlook
Category: Plan for change
Tags: Admin Action, Feature Update, User Adoption
History
10/5/2026 Item Added to Message Center
Microsoft Message
To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy. As part of this update, the .msix and .msixbundle file types will be added to the BlockedFileTypes list in the default OWA Mailbox policy and any custom policies created in your tenant. Most organizations are not expected to be affected by this update because these file types are infrequently used. This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments.
Rollout schedule
General Availability (Worldwide, GCC, GCC High, DoD): Rollout begins in early November 2026 and is expected to complete by mid-November 2026.
Impact on your organization
Who is affected
- Exchange Online administrators who manage OWA mailbox policies
- Users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows
Platforms and services
- Outlook for the web
- New Outlook for Windows
- Exchange Online
What will happen
The .msix and .msixbundle file types will be added to the BlockedFileTypes list in all OWA Mailbox policies in your organization, including the default policy and any custom policies created in your tenant.
Users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows will no longer be able to open or download them.
Action required and recommendations
No action is required if your organization does not rely on the .msix or .msixbundle file types. If your organization relies on these file types, we recommend that you add them to the AllowedFileTypes property of your users’ OwaMailboxPolicy objects prior to rollout.
Learn more
- Blocked attachments in Outlook | Microsoft Support
- Set-OwaMailboxPolicy -AllowedFileTypes | Microsoft Learn
- Set-OwaMailboxPolicy -BlockedFileTypes | Microsoft Learn
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.