Microsoft 365 experienced a significant service outage beginning Monday, August 31, disrupting email, authentication, search, collaboration tools, security platforms, and other cloud services used by businesses around the world.
What initially appeared to be primarily an Exchange Online problem quickly expanded into a broader Microsoft 365 incident.
Microsoft is tracking the widespread event as MO1465074, while the Exchange-specific portion of the outage is being tracked separately as EX1464935.
For organizations heavily dependent on Microsoft 365, the incident is another reminder that even highly redundant cloud platforms can experience failures — and businesses need a plan for what happens when critical cloud services become unavailable.
What Happened?
According to Microsoft's service-health information, the incident began on August 31, 2026, at approximately 3:08 PM UTC, or 10:08 AM Central Time.
Microsoft identified the root cause as an issue involving a core authentication configuration used by multiple Microsoft 365 services. Because authentication components are shared across Microsoft's cloud infrastructure, the problem extended beyond Outlook and Exchange Online.
Users began experiencing problems including failed authentication, email delivery delays, unsuccessful mailbox operations, search failures, administrative portal issues, and degraded functionality across multiple Microsoft services.
Microsoft initially investigated the Exchange Online problem under incident EX1464935 before confirming that the authentication issue was affecting a much wider portion of the Microsoft 365 ecosystem.
Which Microsoft Services Were Affected?
The outage was much larger than an Outlook email problem.
Microsoft reported impact involving services and functionality across:
Exchange Online and Outlook — delayed or failed email delivery, connectivity problems, mailbox-operation failures and search issues
Microsoft Teams — calendar and search problems, stale presence information, location-setting problems and some Teams Room devices appearing offline
SharePoint Online — problems loading content, search results, lists, news and other information
OneDrive for Business — synchronization issues, delayed or failed file access, search problems and portions of the service failing to load correctly
Microsoft 365 Copilot — prompts requiring Microsoft 365 organizational data, including email content, could fail
Microsoft Defender XDR — intermittent authorization failures
Microsoft Purview — authorization problems and difficulty accessing administrative and compliance functionality
Microsoft 365 Admin Center — administrators could experience authentication problems
Universal Print — users could have difficulty creating, uploading or retrieving print jobs
Microsoft also reported situations where users didn't necessarily see a complete outage. Instead, applications could display stale information, repeated retries, incomplete results, timeouts or individual features that stopped functioning.
Exchange Online Was Hit Particularly Hard
Exchange Online was one of the most visibly affected services.
Businesses reported problems sending and receiving email, authenticating to Exchange Online and accessing administrative functions.
Microsoft eventually reported widespread recovery of mailbox connectivity and mail flow, although previously queued messages could take additional time to process because of the backlog created during the outage.
Search remained one of the more persistent problems as Microsoft continued restarting affected infrastructure and reapplying its authentication-component fix.
Was This a Cyberattack?
Based on the information Microsoft has released so far, there is currently no indication that this outage was caused by a cyberattack.
Microsoft attributed the incident to a problem involving a core authentication configuration within its infrastructure.
That distinction is important.
An authentication failure can produce symptoms that look similar to a security incident: users suddenly cannot authenticate, administrators lose access to consoles, security products report authorization errors, and applications begin failing.
IT teams should therefore avoid immediately assuming that authentication failures indicate compromised credentials.
At the same time, administrators should never automatically assume an outage is responsible either.
When widespread login problems occur, organizations should verify Microsoft's service-health information while also monitoring their own identity and security logs for suspicious activity.
Why This Matters to Businesses
Microsoft 365 has become core infrastructure for many organizations.
Email is in Exchange Online. Documents live in SharePoint and OneDrive. Employees communicate through Teams. Devices may be managed through Microsoft's cloud services. Identity and authentication are often tied into Microsoft Entra. Security operations may rely on Defender and Purview.
When a shared component such as authentication experiences a significant failure, the effects can ripple through many otherwise separate applications.
The August 31 outage demonstrates an important principle:
Moving infrastructure to the cloud doesn't eliminate outages. It changes how organizations prepare for them.
Cloud services can provide tremendous reliability, security and redundancy, but businesses should still prepare for situations where those platforms become partially or completely unavailable.
What Should Businesses Do During a Microsoft 365 Outage?
The first priority should be determining whether the problem is local or service-wide.
Microsoft recommends that administrators check the Service Health section of the Microsoft 365 Admin Center when cloud-service problems occur. Microsoft also provides a public service-status page for situations where administrators cannot access their tenant.
IT administrators should avoid making unnecessary configuration changes while a confirmed Microsoft outage is underway. Resetting user passwords, rebuilding Outlook profiles, changing DNS, reinstalling applications or modifying authentication policies may introduce additional problems without fixing an upstream Microsoft service failure.
Organizations should also maintain alternative communication methods so employees can receive instructions if Microsoft Teams or Exchange Online becomes unavailable.
Most importantly, critical business data should not rely on a single point of failure.
Microsoft operates the cloud infrastructure, but organizations are still responsible for their business-continuity strategy, data protection and incident-response planning.
Microsoft 365 Backup Still Matters
An outage does not necessarily mean that data has been lost.
However, service availability and data protection are two different issues.
Organizations using Microsoft 365 should maintain appropriate backup and recovery systems for important Exchange Online mailboxes, SharePoint sites, OneDrive data and other business-critical information.
Independent backups become especially important when organizations need to protect themselves against accidental deletion, ransomware, malicious insiders, compromised administrator accounts or longer-term service disruptions.
The Bigger Lesson: Build for Cloud Resilience
Microsoft 365 remains one of the world's most widely used business productivity platforms, and incidents like this do not mean organizations should abandon cloud services.
They do show why IT planning cannot stop after migration.
Businesses should have documented procedures for cloud outages, alternative communication channels, independent backups, administrator access procedures, security monitoring and a method for quickly determining whether an issue originates inside the organization or with a cloud provider.
For managed IT providers and internal technology teams, outage monitoring should be treated with the same urgency as major cybersecurity alerts.
Knowing that Microsoft is experiencing a service disruption can save an IT department hours of unnecessary troubleshooting — and allow the organization to focus instead on communicating with employees and maintaining business operations.
Current Status
As of September 1, 2026, Microsoft had reported substantial recovery of Exchange Online mail connectivity and mail flow.
However, Microsoft was continuing remediation efforts involving affected infrastructure, with residual issues — particularly involving search and dependent Microsoft 365 functions — still being addressed. Microsoft continued to classify the broader event as a Microsoft 365 service degradation.
Because the situation remains active, businesses experiencing Microsoft 365 problems should continue monitoring Microsoft's Service Health dashboard for tenant-specific updates.
How MicroAdvantage Can Help
Cloud platforms simplify IT infrastructure, but organizations still need monitoring, security, backups and a business-continuity plan.
MicroAdvantage helps businesses manage and secure their Microsoft 365 environments, including Exchange Online, Microsoft Teams, SharePoint, OneDrive, Microsoft Defender, Microsoft Entra and Microsoft Intune.
We can help organizations strengthen Microsoft 365 security, implement backup and recovery solutions, monitor service health, protect accounts with modern authentication and MFA, and develop plans to keep employees productive when critical technology services become unavailable.
Need help reviewing your Microsoft 365 environment or developing a stronger cloud backup and continuity strategy? Contact MicroAdvantage to discuss your IT and cybersecurity needs.
BleepingComputer – Massive Microsoft 365 outage causes auth issues, service failures
Coverage of the outage affecting Exchange Online, Teams, SharePoint, OneDrive, Defender XDR, Purview, and other Microsoft 365 services.