Starting in November 2026, Outlook on the web and new Outlook for Windows are set to block users from opening or downloading .msix and .msixbundle attachments by default in Exchange Online. The update adds the extensions to the default and custom OWA mailbox policies; it concerns attachment access in the named clien...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What is Microsoft changing about .msix and .msixbundle email attachments in Outlook on the web and the new Outlook for Windows in November 2. Article summary: In November 2026, Microsoft plans to add `.msix` and `.msixbundle`—Windows application-package formats—to the attachments blocked by default in Outlook on the web and the new Outlook for Windows for Exchange Online mailb. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
Microsoft plans to block .msix and .msixbundle email attachments by default in Outlook on the web and the new Outlook for Windows for Exchange Online, starting in November 2026. Users of those clients will be unable to open or download the attachments unless an administrator allows the file types in the relevant mailbox policy. 2
3
6
The change concerns Outlook on the web and new Outlook for Windows. Microsoft is adding both extensions to BlockedFileTypes in the default OWA mailbox policy and in custom OwaMailboxPolicy policies. That means organizations should check their custom policies too, rather than assuming only users on the default policy are affected. 3
6
9
The available reports identify Exchange Online but do not establish rollout coverage for each government or sovereign cloud environment. Administrators in those environments should verify the change in their own Microsoft 365 Message Center rather than assume it applies—or does not apply—to their tenant.
Once the change reaches a user’s policy, they will not be able to open or download .msix and .msixbundle attachments in either affected client by default. These extensions are used for Windows application packages and bundles. 1
3
This is described as an attachment-access restriction in the named clients. The reporting says users may receive the files but cannot open or download them there; it does not describe the change as rejecting the email during delivery. Nor does the announcement describe a change to classic Outlook for Windows. 1
3
4
Microsoft says the policy change is intended to enhance security. Blocking app-package attachments by default can reduce the chance that users will access and run a malicious package delivered by email. It is a precaution based on file type, not a claim that every .msix or .msixbundle file is harmful. 1
2
If an organization relies on these attachments, administrators should review which OWA mailbox policies apply to affected users and add .msix and .msixbundle to AllowedFileTypes in the relevant policies. The change is intended to preserve access for organizations that explicitly allow these file types. 2
6
10
Before allowing them, assess whether the business need justifies the risk. Avoid relaxing unrelated attachment restrictions as a workaround.
The announced change limits access to two file extensions in two Outlook clients. It is not described as a malware scan or a guarantee that other attachments are safe. Allowing the extensions restores access to those packages, so organizations should continue to use their other security controls and review files before users install them. 1
2
In short: check the policies assigned to users of Outlook on the web and new Outlook for Windows before the November rollout. If .msix files are not part of your workflow, the reports say no action is needed; if they are, allow only the required extensions in the relevant policies. 2
9
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Starting in November 2026, Outlook on the web and new Outlook for Windows are set to block users from opening or downloading .msix and .msixbundle attachments by default in Exchange Online.
Starting in November 2026, Outlook on the web and new Outlook for Windows are set to block users from opening or downloading .msix and .msixbundle attachments by default in Exchange Online. The update adds the extensions to the default and custom OWA mailbox policies; it concerns attachment access in the named clients, not a stated change to email delivery or classic Outlook.
Starting in November 2026, Outlook on the web and new Outlook for Windows are set to block users from opening or downloading .msix and .msixbundle attachments by default in Exchange Online. The update adds the extensions to the default and custom OWA mailbox policies; it concerns attachment access in the named clien...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What is Microsoft changing about .msix and .msixbundle email attachments in Outlook on the web and the new Outlook for Windows in November 2. Article summary: In November 2026, Microsoft plans to add `.msix` and `.msixbundle`—Windows application-package formats—to the attachments blocked by default in Outlook on the web and the new Outlook for Windows for Exchange Online mailb. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
Microsoft plans to block .msix and .msixbundle email attachments by default in Outlook on the web and the new Outlook for Windows for Exchange Online, starting in November 2026. Users of those clients will be unable to open or download the attachments unless an administrator allows the file types in the relevant mailbox policy. 2
3
6
The change concerns Outlook on the web and new Outlook for Windows. Microsoft is adding both extensions to BlockedFileTypes in the default OWA mailbox policy and in custom OwaMailboxPolicy policies. That means organizations should check their custom policies too, rather than assuming only users on the default policy are affected. 3
6
9
The available reports identify Exchange Online but do not establish rollout coverage for each government or sovereign cloud environment. Administrators in those environments should verify the change in their own Microsoft 365 Message Center rather than assume it applies—or does not apply—to their tenant.
Once the change reaches a user’s policy, they will not be able to open or download .msix and .msixbundle attachments in either affected client by default. These extensions are used for Windows application packages and bundles. 1
3
This is described as an attachment-access restriction in the named clients. The reporting says users may receive the files but cannot open or download them there; it does not describe the change as rejecting the email during delivery. Nor does the announcement describe a change to classic Outlook for Windows. 1
3
4
Microsoft says the policy change is intended to enhance security. Blocking app-package attachments by default can reduce the chance that users will access and run a malicious package delivered by email. It is a precaution based on file type, not a claim that every .msix or .msixbundle file is harmful. 1
2
If an organization relies on these attachments, administrators should review which OWA mailbox policies apply to affected users and add .msix and .msixbundle to AllowedFileTypes in the relevant policies. The change is intended to preserve access for organizations that explicitly allow these file types. 2
6
10
Before allowing them, assess whether the business need justifies the risk. Avoid relaxing unrelated attachment restrictions as a workaround.
The announced change limits access to two file extensions in two Outlook clients. It is not described as a malware scan or a guarantee that other attachments are safe. Allowing the extensions restores access to those packages, so organizations should continue to use their other security controls and review files before users install them. 1
2
In short: check the policies assigned to users of Outlook on the web and new Outlook for Windows before the November rollout. If .msix files are not part of your workflow, the reports say no action is needed; if they are, allow only the required extensions in the relevant policies. 2
9
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Starting in November 2026, Outlook on the web and new Outlook for Windows are set to block users from opening or downloading .msix and .msixbundle attachments by default in Exchange Online.
Starting in November 2026, Outlook on the web and new Outlook for Windows are set to block users from opening or downloading .msix and .msixbundle attachments by default in Exchange Online. The update adds the extensions to the default and custom OWA mailbox policies; it concerns attachment access in the named clients, not a stated change to email delivery or classic Outlook.