Yaamlabs
Phishing

Outlook will block MSIX installer attachments in November

Outlook on the web and new Outlook for Windows will block .msix and .msixbundle attachments from November 2026. What changes, who it breaks and how to allow it.

By Yaali. October 9, 2026, 6 min read, Phishing, Windows.

Cover illustration of an email envelope with a software package stopped by a glowing shield, with the Yaamlabs logo and the text: Outlook blocks MSIX installer attachments, Nov 2026 rollout, early to mid-month

Microsoft will add two Windows installer formats, .msix and .msixbundle, to the list of attachment types that Outlook on the web and the new Outlook for Windows refuse to open or download. The change was announced on October 5, 2026 in Microsoft 365 Message Center notice MC1488841. Rollout starts in early November 2026 and should finish by mid-November, in the Worldwide, GCC, GCC High and DoD clouds.

If your users read mail in either of those two clients, they will see an MSIX attachment but will not be able to open or save it. Most tenants will not notice, and Microsoft says it expects few organisations to be affected. The teams that do send app packages by email, such as internal developers, packaging teams and vendors shipping line-of-business apps, need an exception in place before the rollout reaches them.

Timeline from mid-November 2023, when four financially motivated groups began abusing MSIX and App Installer, through Microsoft disabling the ms-appinstaller handler on December 28, 2023, the July 2025 block on .library-ms and .search-ms, the MC1488841 notice on October 5, 2026, and the early to mid-November 2026 rollout

How the block works

MSIX is the modern Windows app package format. A .msix file holds one app with its files, manifest and signature, and a .msixbundle holds several versions of the same app for different processor architectures. Double-clicking one opens App Installer, which shows the publisher name and an Install button. Outlook already blocks .exe, .msi and the older .appx package format, so .msix was a gap in that list.

The block lives in Exchange Online, in the Outlook on the web mailbox policy (OwaMailboxPolicy). Each policy has a BlockedFileTypes list of extensions that users cannot save or view from Outlook on the web, and an AllowedFileTypes list of extensions that they can. Microsoft will append .msix and .msixbundle to BlockedFileTypes in the default policy and in every custom policy in the tenant. MC1488841 applies the same change to the new Outlook for Windows.

The message itself is still delivered. The attachment stays in the mailbox, and the policy only decides whether those two clients let the user open or download it. MC1488841 names only Outlook on the web and the new Outlook for Windows. Classic Outlook for Windows uses its own blocked attachment list, and Microsoft's current support page for that list includes .appx but not .msix, so do not assume classic Outlook users are covered.

Microsoft made the same kind of change in July 2025 (notice MC1090702), when it added .library-ms and .search-ms to the default block list after attackers used those Windows shortcut formats in phishing.

What attackers are doing

MSIX became a malware delivery format in late 2023. On December 28, 2023, Microsoft Threat Intelligence reported that since mid-November 2023 four financially motivated groups had used signed MSIX packages and the ms-appinstaller link handler, which let a web page start an App Installer download directly. Microsoft said the attackers likely chose this route because it can bypass Defender SmartScreen and the browser warnings people see when they download an executable.

  • Storm-0569, an access broker, spoofed download sites for Zoom, Tableau, TeamViewer and AnyDesk, and also sent phishing emails linking to them. Its BATLOADER payload led to Cobalt Strike, data theft with Rclone and Black Basta ransomware.
  • Storm-1113 delivered its EugenLoader through MSIX installers behind search ads, then dropped Gozi, Redline, IcedID, SmokeLoader, NetSupport, SectopRAT and Lumma.
  • Sangria Tempest, also known as FIN7, used EugenLoader packages behind Google ads to install the Carbanak backdoor.
  • Storm-1674 sent Teams messages from attacker-created tenants with fake OneDrive and SharePoint pages that served packages dropping SectopRAT or DarkGate.

Microsoft disabled the ms-appinstaller handler by default in App Installer 1.21.3421.0 the same day. That closed the link route. A .msix file attached to an email still opens App Installer when double-clicked, and the November change stops that in the two web-based clients.

What to do

Four steps before the November rollout: find who receives MSIX files with an EmailAttachmentInfo query, scope exceptions with a separate OWA mailbox policy, close other paths with the anti-malware attachment filter and App Installer settings, and check devices for installed packages

Find out whether anyone relies on these files. If you run Microsoft Defender for Office 365 Plan 2, this advanced hunting query lists MSIX attachments received in the last 30 days:

EmailAttachmentInfo
| where Timestamp > ago(30d)
| where FileName endswith ".msix" or FileName endswith ".msixbundle"
| project Timestamp, SenderFromAddress, RecipientEmailAddress, FileName, SHA256

Senders you recognise, such as a software vendor or your own build pipeline, point to a workflow that will break. Unknown senders are a lead for the compromise checks below.

Allow the formats only where they are needed. Rather than opening the default policy for everyone, create a policy for the people who handle packages and assign it to them:

New-OwaMailboxPolicy -Name "MSIX-Allowed"
Set-OwaMailboxPolicy -Identity "MSIX-Allowed" -AllowedFileTypes @{Add=".msix",".msixbundle"}
Set-CASMailbox -Identity user@yourtenant -OwaMailboxPolicy "MSIX-Allowed"

Microsoft's guidance is to add the types to AllowedFileTypes before the rollout. Its own Set-OwaMailboxPolicy documentation contradicts itself on whether the allow list or the block list wins when an extension appears in both, so after mid-November run Get-OwaMailboxPolicy | Format-List Name,AllowedFileTypes,BlockedFileTypes and test with a real attachment. A better long-term fix is to move app distribution to Intune, a package feed or a file share, so installers do not travel by email at all.

Cover the clients the policy does not reach. Exchange Online Protection's anti-malware policy has a common attachments filter that blocks file types at delivery, for every client. MSIX is one of the types that filter supports. Check your list with Get-MalwareFilterPolicy -Identity Default | Select-Object -ExpandProperty FileTypes and add msix if it is missing, unless the hunting query above showed a business need.

Keep the App Installer protections on. Confirm the EnableMSAppInstallerProtocol Group Policy is not set to Enabled, and update App Installer to 1.24.2411.0 or later, which adds a SmartScreen reputation check on the download address. (Get-AppxPackage Microsoft.DesktopAppInstaller).Version shows the installed version.

Check whether a package was already installed. On any machine whose user received an unexpected MSIX file, run Get-AppxPackage | Select-Object Name, Publisher, InstallLocation and look for apps with a publisher you do not recognise or a name that imitates Zoom, AnyDesk or TeamViewer. The Microsoft-Windows-AppXDeploymentServer/Operational event log records package installs. If you find a malicious package, isolate the device, remove the package, treat the user's passwords and sessions as stolen, and look for remote access tools such as NetSupport, which these groups installed for follow-on access.

Attachment blocking is one control in a layered setup, and the hard part is knowing which business workflows depend on the formats you are about to block. Our safeguarding and hardening work includes reviewing Exchange Online attachment and anti-malware policies, and security operations covers hunting for installer-based phishing like the campaigns above. If you want help planning the exception list before November, open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: MC1488841 (Message Center mirror), Windows Report, BetaNews, Microsoft Security Blog: threat actors misusing App Installer, MSRC: Microsoft addresses App Installer abuse, Microsoft Learn: Set-OwaMailboxPolicy, Microsoft Support: Blocked attachments in Outlook, MC1090702 (Message Center mirror).

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.