US Edition
Your source for latest news
TechnologyCloud Infrastructure

Microsoft 365 Limps Back After Daylong Outage Tied to Authentication Failure

A misconfigured authentication system knocked Outlook, Teams, SharePoint and Microsoft's security tools offline for businesses worldwide for more than a day, the second such incident to hit the company's flagship productivity suite in 2026.

PT
By PressTemps Technology DeskPublished Today, 21:16 ET · 5 min read
Microsoft 365 Limps Back After Daylong Outage Tied to Authentication Failure
Generic illustrative photo of data-center network cabling, not Microsoft's own facilities. Photo: Taylor Vick / Unsplash
What to know
Microsoft 365 outage began August 31 with Exchange Online and spread within hours to Teams, SharePoint, OneDrive, Copilot, Purview and Defender XDR
Microsoft attributed the failure to a misconfiguration in a core authentication component shared across its cloud services, tracked as incidents EX1464935 and MO1465074
Downdetector logged a peak of nearly 50,000 Outlook complaints, with over a third of users reporting failures receiving email
Core Exchange Online mail flow and search were restored by 12:02 p.m. Eastern on September 1, about 22 hours after Microsoft first acknowledged the incident, though full recovery across all services was still in progress
This marks the second major Microsoft 365 outage of 2026, after a roughly 11-hour incident in January that hit the same cluster of email, security and collaboration services for a different reason

Microsoft 365 was still recovering Tuesday from a widespread outage that began the previous afternoon and cut off email, chat, file storage and internal security tools for businesses around the world, in one of the longer disruptions to hit the company's cloud productivity suite this year.

The trouble started with Exchange Online, Microsoft's hosted email service, before spreading within hours to Microsoft Teams, SharePoint Online, OneDrive for Business, Microsoft 365 Copilot, the compliance platform Purview and the security suite Defender XDR. Microsoft traced the failure to what it called an issue in a "core authentication configuration" shared across multiple services, according to updates the company posted through its official Microsoft 365 Status account, meaning a single broken component was able to take down email, chat and document access at once.

What happened, and when

Microsoft logged the incident internally as EX1464935 shortly before noon UTC on Monday, August 31, and confirmed it publicly at 5:30 p.m. UTC after user reports mounted, according to BleepingComputer's reconstruction of the timeline. Within about three hours the disruption had widened well beyond email, prompting Microsoft to open a second, broader tracking number, MO1465074, to cover the services affected outside Exchange Online.

Engineers first pinned the fault on an authentication component and said they were testing a fix on a portion of Microsoft's infrastructure before rolling it out further, the company said in a post on its status account. By the following morning, the diagnosis had sharpened.

"Our investigation indicates that a misconfiguration issue may be preventing authentication components from deploying as expected to a portion of infrastructure, and we're reexamining recent changes made to the service to determine why this is occurring," Microsoft said in an update posted to its Microsoft 365 Status feed.

Microsoft said Tuesday that core Exchange Online functions, including mail flow and search, had been restored as of 12:02 p.m. Eastern time, roughly 22 hours after the incident was first acknowledged, but cautioned that some services, including search indexing across the wider suite, would take longer to fully stabilize as backlogged data was processed, according to TechCrunch's reporting on the recovery.

The numbers

Outage-tracking site Downdetector recorded a rapid escalation in user complaints as the incident spread on Monday: about 3,000 reports of Outlook problems within minutes of the first spike, climbing past 13,000 within half an hour and reaching nearly 50,000 reports at its peak in the late morning Pacific time, according to figures reported by GV Wire. The largest single category of complaints, more than a third, involved failures to receive email.

Computerworld tracked at least eight distinct status updates from Microsoft over roughly 15 hours on Monday alone, as the company moved from isolating the fault to testing a rollback, to applying a targeted mitigation across affected infrastructure. Search functionality inside Exchange Online was still showing only "incremental improvement" as of early Tuesday, more than a full day after the first reports.

A familiar failure point

This was the second major disruption to Microsoft 365 in 2026. A separate incident on January 22 knocked out Outlook, Defender and Purview portals, and Teams for roughly 10 hours and 50 minutes, which Microsoft attributed at the time to elevated service load and capacity constraints compounded by a third-party networking problem, according to a report from The Register on that incident. Monday's failure hit largely the same cluster of services — email, security tooling and collaboration apps — but stemmed from a different root cause: a misconfigured authentication layer rather than a capacity shortfall.

The repeat pattern points to a structural feature of Microsoft 365 rather than a one-off mistake. Exchange Online, Teams, SharePoint, Defender and Purview all sit behind the same identity and authentication backbone, so a fault in that shared layer can cascade across services that otherwise have little in common. Enterprise customers who rely on Microsoft for both productivity software and security monitoring were effectively left without either at the same time, since Defender XDR — the tool many of them use to detect intrusions — was itself degraded during the outage. Two significant outages inside eight months on a suite used by hundreds of millions of paying seats revive a recurring question in enterprise IT circles about the risk of concentrating email, collaboration, compliance and security functions with a single cloud vendor, rather than spreading them across independent providers.

Who was affected, and what happens next

The outage landed on a Monday, when enterprise email and collaboration traffic is typically at its heaviest, disrupting corporate correspondence, calendar bookings and file sharing for businesses across North America, Europe and beyond that rely on Microsoft's cloud suite for day-to-day operations. Organizations that also depend on Purview for compliance record-keeping or Defender XDR for security monitoring faced gaps in those functions as well.

Remote and hybrid workers were among the most exposed, since a functioning connection to Exchange Online and Teams is often a prerequisite for reaching colleagues at all when a workforce is not physically together. Universities, government offices and large employers were among the organizations that posted their own service-status notices directing staff to the underlying Microsoft incident, a sign of how far downstream the disruption reached beyond Microsoft's own dashboards.

Microsoft has not detailed a formal post-incident review, but it said its focus had shifted to validating recovery across the full range of affected services and clearing backlogged mail queues that built up during the disruption. Customers can continue to track the incident under reference numbers EX1464935 and MO1465074 in the Microsoft 365 admin center. The company has not said whether it will publish a public root-cause analysis, something it has done for past incidents of comparable scale, nor given a specific timeline for when every affected service, including search and Copilot features that lean on it, will be back to full strength.

More on this story

All Technology