Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft extends the Outlook naughty step with two more file types

You didn't really want to be sending around .msix and .msixbundle files, did you?

Microsoft extends the Outlook naughty step with two more file types

Microsoft is expanding its Outlook file type block list with two additional extensions, .msix and .msixbundle, to enhance security measures. These file types, utilized for Windows application packages and bundles, will be disabled by default for New Outlook for Windows and Outlook on the Web in Exchange Online. This move aims to prevent the automatic download or opening of potentially malicious attachments that, if installed, could compromise a device.

Though infrequently used, legitimate reasons for their presence in emails exist. Administrators can permit these attachments by adding the extensions to the AllowedFileTypes property of the appropriate OwaMailboxPolicy before the scheduled update, set for early to mid-November 2026. Microsoft's decision to bolster security comes after previous concerns over the Windows application packaging system, which faced attacks in the past.

Despite the addition of .msix and .msixbundle to the blocked file list, other file types like .py Python files, .ps1 PowerShell files, and .cab files remain restricted in Outlook on the Web. While renaming an attachment's extension or sending a download link might bypass the restriction, these actions do not guarantee the safety of the package.

Persuading someone to download and install the file remains a potential threat, even with the added security measures in place.

Written by urgent.news from The Register Software's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Tuesday 6 October →