Microsoft Adds .XLSB and .XLTM Files to Outlook Attachment Block List

Microsoft has expanded its restrictions on file types that can be opened directly from emails in Outlook, adding two more formats to a growing list of blocked attachments. The software giant announced the change as part of ongoing efforts to reduce the risk of malware delivered through common office document vectors. The update, which takes effect in stages over the coming months, prevents users from launching .xlsb and .xltm files straight from messages without first saving them to disk.

This decision follows a pattern established earlier this year when Microsoft added several other Excel and Word formats to the naughty step. Security researchers have long warned that macro-enabled spreadsheets and templates represent attractive targets for attackers because they can contain executable code that runs automatically under certain conditions. By forcing users to save these files first, Microsoft adds an extra layer of friction that can interrupt many automated attack chains.

The two new additions bring the total number of restricted file types in Outlook to more than a dozen. Excel Binary Workbook files, which use the .xlsb extension, offer smaller file sizes and faster processing for complex calculations but also support embedded macros. Similarly, .xltm files are macro-enabled Excel templates that users often rely on to standardize formatting and automate repetitive tasks across organizations. Both formats can execute Visual Basic for Applications code, the same scripting language that has powered countless malware campaigns over the past two decades.

According to reporting from The Register, the change will appear first in the beta channel of Microsoft 365 before rolling out more broadly. Organizations using on-premises Exchange servers or older perpetual license versions of Outlook will receive the update through monthly security patches. Microsoft has not provided an exact timeline for every supported platform, but administrators should expect to see the behavior change in Outlook for Windows, the new Outlook for Windows, and Outlook on the web within the next several release cycles.

The move reflects a broader shift in how Microsoft approaches attachment security. For years the company relied primarily on warnings and user education to discourage opening suspicious files. Those warnings proved insufficient as attackers grew more sophisticated at crafting convincing social engineering lures. Research from multiple security firms shows that macro-enabled documents remain among the top delivery mechanisms for ransomware and information-stealing malware despite repeated attempts to disable macros by default.

By blocking direct execution from within Outlook, Microsoft forces users through a conscious decision point. The file must be saved locally, after which standard Windows protections such as Mark of the Web and Windows Defender SmartScreen can apply additional scrutiny. This approach mirrors similar restrictions already in place for .docm, .xlsm, .pptm and several other formats that Microsoft introduced in previous updates. Each expansion of the list has sparked debate among power users who rely on legitimate macros for business processes.

Enterprise administrators face particular challenges with this policy. Many organizations have built extensive libraries of macro-enabled templates that employees open directly from shared mailboxes or automated notification systems. Disrupting that workflow could reduce productivity unless IT teams update internal procedures. Microsoft recommends that companies hosting such templates move them to SharePoint or OneDrive locations where users can download them through controlled channels that maintain proper security context.

Security professionals generally view the change positively even if it creates short-term inconvenience. Phil Stokes, a malware analyst who has tracked Office-based threats for years, noted in independent research that attackers frequently chain multiple Office file types together to bypass initial detection. Adding .xlsb and .xltm to the blocked list closes another avenue that threat actors had begun to favor after earlier formats faced increased scrutiny.

The timing of this announcement coincides with a noticeable uptick in campaigns targeting financial and healthcare sectors using sophisticated Excel-based loaders. Threat intelligence teams at several vendors reported seeing .xlsb files used to deliver custom backdoors that communicate over encrypted channels. These files often masquerade as financial reports or inventory spreadsheets, taking advantage of the format’s ability to handle large datasets without performance degradation.

Microsoft’s decision also aligns with guidance from government cybersecurity agencies. Both CISA and the UK’s NCSC have published recommendations urging organizations to treat macro-enabled files with suspicion and to avoid opening attachments directly from email clients whenever possible. The agencies specifically highlight the danger of binary formats that can hide malicious code more effectively than standard XML-based Office files.

For individual users, the practical impact will vary depending on how they interact with email. Casual consumers who rarely receive spreadsheets as attachments may never notice the difference. Power users and those working in finance, accounting, or data analysis roles will likely encounter more frequent prompts to save files before opening them. Microsoft has implemented the restriction at the attachment handler level, meaning double-clicking the file icon in an email message will trigger a dialog explaining that the file type has been blocked for security reasons.

The company has provided administrators with Group Policy settings and cloud-based configuration options to manage the behavior. Organizations that need to maintain legacy workflows can create exemption lists for specific file types, though Microsoft strongly discourages broad exemptions. The preferred approach involves training users to save attachments to a designated folder where security tools can scan them thoroughly before opening.

This latest expansion continues a trend that began in 2022 when Microsoft started disabling macros by default across all Office applications. That initial change dramatically reduced the success rate of macro-based malware but also pushed attackers toward alternative vectors including JavaScript-based attachments, archive files containing malicious scripts, and HTML smuggling techniques. Each defensive improvement by Microsoft appears to stimulate corresponding innovation from the adversary community.

Looking ahead, security experts anticipate further restrictions on additional file types. Formats like .dotm for Word templates and certain Publisher files have been mentioned in industry discussions as candidates for future blocks. Microsoft has indicated that it evaluates file types based on their prevalence in malicious campaigns, the complexity of their security model, and the availability of safer alternatives for legitimate use cases.

The company has also invested heavily in cloud-based attachment scanning through Microsoft Defender for Office 365. This service detonates suspicious files in sandbox environments before delivering them to users’ inboxes. When combined with the new restrictions on direct execution, these layered defenses create multiple hurdles for attackers attempting to compromise endpoints through email.

Despite the benefits, some critics argue that Microsoft could do more to provide granular controls and better documentation for affected organizations. The rollout of previous attachment blocks caught many IT departments by surprise, leading to helpdesk tickets and temporary productivity dips. Clearer communication about upcoming changes and more comprehensive migration guidance would help smooth the transition.

For developers who create legitimate macro-enabled solutions, the changing environment requires adaptation. Many have already moved toward Microsoft 365 Add-ins built with web technologies that run in a more restricted security context. Others have migrated business logic to Power Automate flows or custom applications that don’t rely on client-side macros. These modern approaches offer better security postures while maintaining functionality.

The broader lesson from Microsoft’s ongoing adjustments to Outlook attachment handling is that security improvements often involve trade-offs between protection and convenience. Each new restriction reduces the attack surface but also alters established user habits. Organizations that invest time in updating policies, training staff, and modernizing workflows tend to experience fewer disruptions when these changes arrive.

As threat actors continue to evolve their tactics, email remains the primary entry point for many cyberattacks. Microsoft’s incremental approach to blocking risky file types represents one component of a larger strategy that includes improved authentication, better detection of phishing attempts, and tighter integration between email security and endpoint protection. While no single measure can eliminate the threat entirely, each addition to the blocked list makes successful compromise more difficult and more expensive for attackers.

Users who encounter the new restriction will see a clear message explaining why the file cannot be opened directly and offering the option to save it instead. This explicit feedback helps reinforce security awareness by making the risks visible at the moment of interaction. Over time, such repeated nudges can shift user behavior toward safer practices without requiring constant training sessions.

The addition of .xlsb and .xltm files to Outlook’s restricted list demonstrates the company’s willingness to prioritize security even when it affects popular file formats. As attackers develop new techniques, Microsoft will likely continue expanding these protections. Organizations and individual users alike should prepare for further changes by reviewing their document workflows and adopting safer alternatives where possible. The balance between functionality and protection remains delicate, but the direction is clear: direct execution of potentially dangerous file types from within email clients faces increasing limitations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top