TechPolicy Record

EU tech rules, stage by stage

RSS

Big Tech in Europe

Microsoft sets November Outlook block for .msix attachments

Notice MC1488841 adds .msix and .msixbundle to Outlook web policies in Exchange Online, with rollout beginning in early November.

thenextweb.com
thenextweb.com Kaynak yayıncı

Microsoft’s notice MC1488841, published on 5 October, sets out a policy change covering .msix and .msixbundle attachments. From early November, Outlook on the web and new Outlook for Windows will stop users opening or downloading those files. The change applies to Exchange Online tenants through their default and custom policies.

What policy stage has Microsoft announced?

This is a planned product-policy change, rather than a regulatory measure or a reported enforcement decision. The notice says both formats will be added to the default Outlook web mailbox policy and to each custom policy in a tenant. The rollout is expected to run from early November to mid-month.

Microsoft is the authority for the product change described in the notice. The source material does not identify a regulator, legal proceeding or statutory requirement behind it. It also does not provide a separate company response beyond the stated policy explanation.

Which users and files are covered?

The stated scope is Outlook on the web and new Outlook for Windows. Users of those services will be unable to open or download .msix and .msixbundle attachments once the policy change reaches their tenant. The source does not establish that other Outlook products or methods of file transfer are covered.

MSIX is a Microsoft Windows application packaging format developed to replace .exe and .msi installers. A bundle can hold several builds of one application, with Windows selecting the appropriate build during installation. Microsoft Store apps use the format, according to the source material.

How can an organisation keep receiving them?

Microsoft support documentation says administrators who need these formats must add them to an allowed list before the change. This means an organisation that depends on attachment delivery will need to review its current policy configuration. The source does not provide the technical steps or describe how exceptions are approved within each tenant.

The published account says renaming the extension can still let a package through, and a download link is another route. That information indicates the announced restriction concerns the two attachment extensions. It does not establish that either route is endorsed by Microsoft or that the policy is intended as a complete control against package delivery.

What security basis is described?

Microsoft did not cite a specific attack as the reason for this change. The source connects the formats to an earlier episode involving the ms-appinstaller protocol handler, which Microsoft disabled by default in December 2023. Four financially motivated groups were associated with abuse of that handler: Storm-0569, Storm-1113, Sangria Tempest and Storm-1674.

Microsoft’s threat intelligence team said the groups delivered BATLOADER, EugenLoader, IcedID, DarkGate and Black Basta ransomware. The handler had bypassed Defender SmartScreen and browser warnings for executable downloads. The source does not say that the Outlook attachment policy blocks these malware families or resolves the risks described in that earlier episode.

What remains unclear before rollout?

The notice’s rollout is scheduled to begin in early November and continue to mid-month, but the source does not state an exact date for each tenant. It also does not detail how administrators can confirm that a custom policy has been updated. The supported action described is to add the file types to an allowed list where continued receipt is required.

Outlook on the web previously blocked 104 extensions before September 2019, and Microsoft added 38 more then, according to BleepingComputer. That history places the current change within an existing attachment-policy framework. It does not alter the notice’s stated scope or establish additional obligations for Exchange Online customers.

Administrators can use MC1488841 and Microsoft’s support documentation to assess their configuration. The source provides no further company response on the policy’s rationale or exception process. The next stated milestone is the beginning of the rollout in early November.

Sources

  1. Microsoft will block two Windows installer formats in Outlook from November thenextweb.com