$ techbeacon▋
Threats

Outlook to Ban MSIX Package Files as Attachments Starting November

Outlook to Ban MSIX Package Files as Attachments Starting November

Microsoft will begin preventing the transmission of .msix and .msixbundle files through Outlook Web and the newly released Outlook client for Windows as of November.

The MSIX format, introduced by Microsoft as a modern replacement for older installer packages, bundles an application’s files, registry entries, and configuration data into a single, signed package that can be deployed across Windows devices.

Outlook’s attachment filtering has historically targeted executable content that can carry malware, and the addition of MSIX to the blocked list reflects growing concerns that signed installer packages could be leveraged to bypass security controls.

The change, announced by the company earlier this month, will take effect at the start of the next calendar month and will apply to both the browser‑based Outlook.com service and the “new Outlook” desktop client that Microsoft rolled out to replace the classic version.

For end users, the policy means that attempts to send or receive an MSIX file through the affected clients will result in a delivery failure notice. IT administrators in corporate environments will need to adjust any internal distribution processes that rely on emailing these packages.

Organizations can work around the restriction by using approved file‑sharing platforms such as OneDrive for Business, SharePoint, or third‑party cloud storage, and then sharing a link instead of attaching the package directly.

Microsoft has previously expanded its block list to include other executable formats like .exe, .bat, and script files, a pattern that aligns with industry‑wide efforts to reduce phishing and ransomware vectors that exploit trusted file types.

The company has not indicated whether the policy will be extended to other Outlook clients, such as the classic desktop app or mobile versions, leaving the possibility of further restrictions open as security threats evolve.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related