MC1488841 - Microsoft Outlook: Update to default blocked file types in OwaMailboxPolicy

Message Center

Summary

Outlook on the web and new Outlook for Windows will block .msix and .msixbundle file types by default in OwaMailboxPolicy starting November 2026 to enhance security. Organizations using these file types should whitelist them beforehand; no action is needed if not used.

Published

Oct 5, 2026

Service

Exchange Online

Tag

Major change
Feature update
User impact
Admin impact

More information

What and why

To enhance security in Outlook on the web and new Outlook for Windows, we are updating the default list of blocked file types in OwaMailboxPolicy. As part of this update, the .msix and .msixbundle file types will be added to the BlockedFileTypes list in the default OWA Mailbox policy and any custom policies created in your tenant. Most organizations are not expected to be affected by this update because these file types are infrequently used. This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments.

Rollout schedule

  • General Availability (Worldwide, GCC, GCC High, DoD): Rollout begins in early November 2026 and is expected to complete by mid-November 2026.

Impact on your organization

Who is affected

  • Exchange Online administrators who manage OWA mailbox policies
  • Users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows

Platforms and services

  • Outlook for the web
  • New Outlook for Windows
  • Exchange Online

What will happen

  • The .msix and .msixbundle file types will be added to the BlockedFileTypes list in all OWA Mailbox policies in your organization, including the default policy and any custom policies created in your tenant.
  • Users who send or receive .msix or .msixbundle attachments in Outlook on the web or new Outlook for Windows will no longer be able to open or download them.

Action required and recommendations

No action is required if your organization does not rely on the .msix or .msixbundle file types. If your organization relies on these file types, we recommend that you add them to the AllowedFileTypes property of your users' OwaMailboxPolicy objects prior to rollout.

Learn more

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.