Microsoft to Block MSIX and MSIXBundle Attachments in Outlook This November
Moyen · BleepingComputer ·
En bref
- Microsoft will prevent MSIX and MSIXBundle files from being attached in Outlook.
- The change applies to Outlook on the web and the new Outlook for Windows client.
- Rollout begins in November; no CVE is associated with this update.
- The move is a preventive step against attackers using signed installers to bypass email filters.
- Admins should review transport rules and prepare user communications now.
Microsoft has announced that beginning in November, its email platform will begin rejecting messages that carry MSIX and MSIXBundle packages as attachments. The change applies across Outlook on the web and the newer Outlook for Windows desktop client, with the company adding these file extensions to its existing roster of prohibited attachment types.
The move is a direct response to abuse by threat actors, who have increasingly turned to these installer formats as a way to bypass conventional email defenses. Because MSIX packages can contain executable code and are signed, they can appear trustworthy while still delivering unwanted payloads. By placing these extensions on the blocked list, Microsoft aims to cut off a common delivery path before a user can open the file.
K-12 districts and other organizations using Microsoft 365 are affected. Staff and students accessing mail through a browser or the refreshed Windows Outlook app will no longer be able to send or receive these attachment types. The classic Outlook desktop client and third-party mail clients may behave differently, so local filtering rules and user guidance will still matter.
The timing — next month — gives administrators a short window to prepare. No CVE is associated with this change; it is a preventive configuration update rather than a patch for a known vulnerability. Still, the risk is meaningful because email remains a primary entry point for ransomware and credential theft.
What to watch: Microsoft's official rollout schedule, any exceptions for trusted senders, and whether the block extends to other clients. Admins should also monitor for legitimate business use of MSIX packages that could be disrupted.
À faire maintenant
- Add .msix and .msixbundle to your Exchange Online transport rules' blocked attachment list if not already inherited.
- Verify that the block applies to both Outlook on the web and the new Outlook for Windows client.
- Notify help desk staff and end users about the upcoming change and provide an alternative for legitimate file sharing.
- Review mail flow reports for MSIX and MSIXBundle attachments over the last 30 days to spot potential attack attempts.
- Test inbound and outbound messages containing these extensions to confirm enforcement before November.
- Update security awareness training to remind users never to open unexpected installer files.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.