Microsoft announced significant security enhancements for Outlook Web and the New Outlook for Windows, introducing new restrictions on file attachments commonly exploited by cybercriminals.
Starting in early July 2025, the technology giant will block two specific file types that have become frequent tools in malicious campaigns targeting email users.
The company will add .library-ms and .search-ms file extensions to its default blocked file types list in the OwaMailboxPolicy.
These file formats, while rarely used in legitimate business communications, have gained notoriety among threat actors for their ability to bypass traditional security measures and execute malicious code on target systems.
The rollout represents Microsoft’s continued commitment to proactive cybersecurity in its email platforms.
The blocked file types will be automatically added to both the default OWA Mailbox Policy and any custom policies organizations have created within their tenants.
This comprehensive approach ensures uniform protection across all Outlook Web and New Outlook for Windows installations.
Microsoft emphasizes that most organizations will experience minimal disruption from these changes. The affected file types have limited legitimate use cases in typical business environments, making the security enhancement largely transparent to everyday users.
However, organizations that rely on these specific file formats for operational needs have options to maintain functionality.
IT administrators who require these file types for legitimate business purposes can proactively add them to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects before the July rollout begins.
This granular control allows organizations to balance security requirements with operational needs. The automatic implementation means no action is required for most organizations.
Users who attempt to send or receive the newly blocked file types will find they cannot open or download these attachments through Outlook Web or the New Outlook for Windows interface.
This announcement reflects the ongoing cybersecurity arms race between technology companies and malicious actors. Email remains a primary attack vector for cybercriminals, with attachment-based threats continuing to evolve in sophistication.
By preemptively blocking file types with minimal legitimate use but high abuse potential, Microsoft aims to reduce the attack surface available to threat actors.
The move aligns with industry-wide efforts to implement zero-trust security models, where potentially risky elements are blocked by default rather than allowed until proven malicious.
This proactive stance represents a shift from reactive security measures to preventive protection strategies. Organizations should review their current email security policies and communicate these changes to users who might be affected.
While the impact is expected to be minimal, advance preparation ensures smooth operations during the transition period beginning in early July 2025.
Live Credential Theft Attack Unmask & Instant Defense – Free Webinar
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…