Cyber Security News

Microsoft to Block Attachments in Outlook Web & Windows Used by Threat Actors

Microsoft announced significant security enhancements for Outlook Web and the New Outlook for Windows, introducing new restrictions on file attachments commonly exploited by cybercriminals.

Starting in early July 2025, the technology giant will block two specific file types that have become frequent tools in malicious campaigns targeting email users.

The company will add .library-ms and .search-ms file extensions to its default blocked file types list in the OwaMailboxPolicy.

  • .library-ms
  • .search-ms

These file formats, while rarely used in legitimate business communications, have gained notoriety among threat actors for their ability to bypass traditional security measures and execute malicious code on target systems.

Microsoft to Block Attachments

The rollout represents Microsoft’s continued commitment to proactive cybersecurity in its email platforms.

The blocked file types will be automatically added to both the default OWA Mailbox Policy and any custom policies organizations have created within their tenants.

This comprehensive approach ensures uniform protection across all Outlook Web and New Outlook for Windows installations.

Microsoft emphasizes that most organizations will experience minimal disruption from these changes. The affected file types have limited legitimate use cases in typical business environments, making the security enhancement largely transparent to everyday users.

However, organizations that rely on these specific file formats for operational needs have options to maintain functionality.

IT administrators who require these file types for legitimate business purposes can proactively add them to the AllowedFileTypes property of their users’ OwaMailboxPolicy objects before the July rollout begins.

This granular control allows organizations to balance security requirements with operational needs. The automatic implementation means no action is required for most organizations.

Users who attempt to send or receive the newly blocked file types will find they cannot open or download these attachments through Outlook Web or the New Outlook for Windows interface.

This announcement reflects the ongoing cybersecurity arms race between technology companies and malicious actors. Email remains a primary attack vector for cybercriminals, with attachment-based threats continuing to evolve in sophistication.

By preemptively blocking file types with minimal legitimate use but high abuse potential, Microsoft aims to reduce the attack surface available to threat actors.

The move aligns with industry-wide efforts to implement zero-trust security models, where potentially risky elements are blocked by default rather than allowed until proven malicious.

This proactive stance represents a shift from reactive security measures to preventive protection strategies. Organizations should review their current email security policies and communicate these changes to users who might be affected.

While the impact is expected to be minimal, advance preparation ensures smooth operations during the transition period beginning in early July 2025.

Live Credential Theft Attack Unmask & Instant Defense – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago