NEWS
Microsoft Outlook Outage Spread Through Shared Authentication Config
Microsoft Outlook failed Aug. 31 after a shared Microsoft 365 sign-in config broke, dragging Teams, Copilot and Defender into a day-long recovery.
A core authentication-configuration fault knocked Microsoft Outlook and Exchange Online offline for much of Monday, Aug. 31, and pulled other Microsoft 365 services with it. Downdetector logged more than 6,000 Outlook problem reports by 8:17 a.m. PT. Microsoft later traced the mess to sign-in settings shared across the suite, not to a defect inside the mail client.
By Tuesday afternoon, mail flow and search were back. Copilot, Defender, Teams, and SharePoint were still being checked against the same fault.
A Shared Login Layer Took the Suite Down
The public story opened as an Outlook outage. The ticket Microsoft filed was broader. Exchange Online was logged as incident EX1464935 after users could not send, receive, search, or even sign in. A second ticket, MO1465074, then covered other Microsoft 365 apps that share the same sign-in path.
Microsoft told customers the root was “an issue within a core authentication configuration used by multiple Microsoft 365 services.” That sentence is the whole event. Mail did not fail alone. The settings that mint and check sessions failed to land on part of the fleet, so any product waiting on a fresh token felt it.
A Microsoft spokesperson said the company knew access to Exchange Online and some other services was broken, called the disruption hard on customers, and pointed people to status updates while engineers worked. Those updates sat on the Microsoft 365 service health status page and on the @MSFT365Status account.
We’ve identified issues related to a core authentication configuration used by multiple internal services within the Exchange Online infrastructure. We’re performing a manual test on the individual server level to reset to configurations to validate if this resolves the issue.
Microsoft, admin center update on EX1464935
That server-level reset is why the outage never looked like a clean on/off switch. Some desks stayed live. Others never got in. The products that share tokens the identity platform issues moved together, for better and then for worse.
Monday’s Fix Started as a Server-by-Server Reset
University of Pennsylvania IT, reading Microsoft’s admin console, put the first internal look at 11:55 a.m. UTC on Aug. 31. By 12:33 p.m. UTC, Microsoft said it had isolated a common failure pattern in Exchange Online requests tied to sign-in and protocol connectivity. The broader incident’s official start time was later set at 3:08 p.m. UTC.
Engineers spent the afternoon asking why authentication components were not deploying as expected after recent changes, and whether they could safely restore those components, including by reverting an update the affected gear had just received. Mitigation tests turned positive by 5:55 p.m. UTC. At 6:40 p.m. UTC they began reapplying the components on a sample of servers and said some users were already seeing relief.
THE OUTAGE FROM FIRST ALERT TO SEARCH RECOVERY
- 11:55 a.m. UTC, Aug. 31: Microsoft starts investigating a rise in Exchange Online trouble reports.
- 3:08 p.m. UTC, Aug. 31: The company sets this as the official start of the broader Microsoft 365 incident MO1465074.
- 4:36 p.m. UTC, Aug. 31: Microsoft reexamines recent changes and studies a revert of an update on the affected systems.
- 8:50 p.m. UTC, Aug. 31: Microsoft 365 Status says a misconfiguration may be blocking authentication components from deploying as expected.
- 11:47 p.m. UTC, Aug. 31: The firm deploys the fix more widely and restarts targeted sections of the fleet to help mail flow.
- 3:52 a.m. UTC, Sep. 1: Mailbox connectivity is back inside expected thresholds; search is still the priority.
- 3:57 p.m. UTC, Sep. 1: Microsoft confirms mail flow and search have recovered and turns to dependent services.
The first public thread from Microsoft 365 Status opened while that work was still a test on a slice of servers, not a fleet-wide all-clear.
https://x.com/MSFT365Status/status/2094455556454920701
Verification Emails Failed First, Then the Inbox
The outage did not arrive as one error code. It arrived as a pile of small refusals that changed as the day wore on. Offices reported mixed luck in the same room, with one mailbox dead and the next one fine. That pattern fits a partial deploy: the broken config reached some servers and skipped others.
The nastier cut was the closed loop. People who needed a verification message to prove who they were could not get the message, because mail was the thing that was down. Sign-in and the inbox failed together, so the usual “reset the password, grab the code, come back” path had nowhere to land. Staying inside an already-open Outlook session was, for some, safer than restarting the app and asking for a new token.
Microsoft’s own Exchange Online symptom list, posted to admins, matches that scatter.
WHAT EXCHANGE ONLINE FAILED TO DO
- Mail flow: Delays or failures when sending or receiving messages, including on Outlook for iOS and Android.
- Mailbox search: Delays, failures, or incomplete results when looking for content inside Exchange Online.
- Sign-in errors: Authentication-related errors when clients tried to reach Exchange Online services.
- Admin tools: Trouble accessing or acting inside Exchange administration experiences.
- Mailbox jobs: Intermittent failures in mailbox operations and message-delivery workflows.
Downdetector’s mix among people who filed Outlook reports was 37 percent on receiving messages, 23 percent on the app, and 20 percent on the website. One early complaint was simpler than any of those buckets: the site would not open, and when it did, search was dead.
Search Stayed Broken After Mail Came Back
Mail moved first. Search did not. Late Monday, Microsoft said users should start seeing gradual recovery in mail flow while it restarted targeted sections of the affected systems. By 10 p.m. ET, delivery was improving and search was still degraded. Shortly after 3 a.m. ET on Tuesday, search telemetry began to look better.
Overnight posts from Microsoft 365 Status kept splitting the two. At 5:24 a.m. UTC on Sep. 1 the account said mail flow was working as expected and queues were draining, with search still the focus. A later note at 7:08 a.m. UTC said search telemetry had improved and recovery work was continuing. That lag matters in a workday: a mailbox that accepts new mail but cannot find last week’s thread is only half a mailbox.
Downdetector had already cooled by Tuesday morning on the West Coast, with fewer than 550 Outlook reports at 6 a.m. PT and fewer than 460 at 6:30 a.m. PT. Residual tickets do not prove a global outage, and they do not prove a full fix. They do show the spike had broken.
At 10:27 a.m. UTC Tuesday, Microsoft said mitigation was still moving through remaining systems, telemetry stayed positive, and the company was entering extended monitoring. Then, at 3:57 p.m. UTC, it drew a sharper line under Exchange itself.
https://x.com/MSFT365Status/status/2094816923594674517
“We’ve confirmed that core Exchange Online experiences, including mail flow and search functionality, have recovered,” Microsoft 365 Status wrote. It was still validating recovery for dependent Microsoft 365 services and integrations. Mail was the headline. The shared config had a longer tail.
Why Copilot and Defender Failed With Outlook
Microsoft listed Exchange Online as the hardest-hit product and still would not call the rest a total outage. What it did publish was a roster of degraded jobs across the suite, all tied to the same core authentication configuration. Copilot prompts that need Microsoft 365 data, including mail, could fail. Defender showed intermittent authorization failures. Teams calendars, search, and presence went stale. SharePoint and OneDrive struggled to load, refresh, search, and sync. The Microsoft 365 admin center and Universal Print were on the same list.
That is the second blow. Security tools and the admin console sit on the same sign-in path as the inbox. Telling customers to “see EX1464935 in the admin center” is a weak instruction if the admin center is one of the patients. Some tenants could still open it. Microsoft had already warned of trouble inside Exchange admin experiences.
HOW THE SHARED CONFIG SHOWED UP BY PRODUCT
| Service | What Microsoft said broke |
|---|---|
| Exchange Online / Outlook | Send and receive, mailbox search, sign-in, admin actions |
| Microsoft Teams | Calendar, search, presence, location updates |
| SharePoint Online and OneDrive | Search, file access, sync, content loading |
| Microsoft 365 Copilot | Prompts that need Microsoft 365 data, including email |
| Microsoft Purview | Delays creating and evaluating Communication Compliance policies |
| Microsoft Defender XDR | Intermittent authorization failures across Defender solutions |
| Admin Center and Universal Print | Listed among the affected Microsoft 365 services |
Copilot’s miss is the cleanest exhibit. The assistant is sold as a layer over mail, files, and meetings. When the sign-in config under those stores wobbles, prompts that need grounding in a mailbox have nothing to stand on. That is a live stress test for the Copilot super app for Microsoft 365, which still drinks from the same Exchange and SharePoint pipes.
Defender’s authorization failures cut the other way. The suite’s threat console is supposed to stay reachable when the rest of the tenant is sick. On Monday it was one more name on the incident list, because it uses the same core config.
Identity Outages Keep Hitting the Same Shared Pipe
This was not the first time a sign-in change took several Microsoft 365 products in one swing. Microsoft’s own post-incident reviews describe an Azure Active Directory update on Sep. 28, 2020 that blocked sign-ins for about five hours and reached Outlook, Teams, and the Azure portal even though those apps were otherwise healthy. On Mar. 15, 2021, an error in authentication key rotation hit Teams, Exchange Online, and even Xbox Live for about two hours.
On Nov. 25, 2024, a problematic change to authentication and token infrastructure disrupted Exchange Online and Teams calendar and mail flow for most of a business day. Microsoft mitigated that one by reverting the change and restarting unhealthy machines. Monday’s playbook looked familiar: inspect recent changes, test a fix on a slice, reapply components, restart targeted servers, watch search lag mail.
PRIOR SIGN-IN FAILURES WITH A WIDE BLAST RADIUS
| Date | What broke | What it hit | How long |
|---|---|---|---|
| Sep. 28, 2020 | Azure AD update with a latent code defect | Microsoft 365 sign-ins, Outlook, Teams, Azure portal | About 5 hours |
| Mar. 15, 2021 | Authentication key rotation error | Teams, Exchange Online, Microsoft 365 sign-ins, Xbox Live | About 2 hours |
| Nov. 25, 2024 | Change to authentication and token infrastructure | Exchange Online, Teams calendar and email flow | Most of a business day |
| Aug. 31, 2026 | Core authentication configuration failed to deploy | Exchange Online plus Teams, SharePoint, Copilot, Defender, Purview | Mail and search recovered in about 22 hours |
Other big Microsoft 365 shocks in the same years came from the network edge rather than identity, including a WAN router change in January 2023 and an Azure Front Door configuration failure on Oct. 29, 2025. The recurring lesson is still narrow. When the shared pipe fails, the apps above it fail as a group, and Exchange Online shows up more often than any other workload because mail needs both identity and routing.
Microsoft Already Missed Its Uptime Bar This Year
Microsoft’s financially backed target for these online services is 99.9 percent monthly uptime. Credits step up as the figure falls, under the published Service Level Agreements for Online Services. A 22-hour incident is not, by itself, a declared SLA breach, because the credit math runs on user-minutes rather than wall-clock hours. It is the kind of event those credits exist to price.
The company’s own worldwide uptime tables for Microsoft 365 already showed strain before this week. For unplanned multi-tenant incidents with broad impact, Microsoft also pledges a preliminary post-incident review within 48 hours of resolution and a final review within five business days.
MICROSOFT 365 UPTIME ON MICROSOFT’S OWN BOOKS
- SLA floor: 99.9 percent monthly uptime is the financially backed commitment for the online services.
- Q1 2026: Worldwide uptime was 99.526%, under that 99.9 percent bar.
- Q2 2026: Worldwide uptime recovered to 99.994 percent.
- Q4 2025: The prior quarter closed at 99.954 percent, also a dip from the 99.99 percent readings common in 2023.
Microsoft 365 Status said Tuesday afternoon that core Exchange Online mail flow and search had recovered and that it was still validating dependent services and integrations. The inbox came back. The shared sign-in config that took Copilot and Defender with it is the part that has to hold the next time someone pushes a change.
-
AI3 months agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI2 months agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI3 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING3 months agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
CRYPTO3 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
NEWS3 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
APPS3 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI3 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
