Summary
On August 31, 2026, Microsoft 365 went down for a large swath of users worldwide. It started with Exchange Online and Outlook, then spread to Teams, SharePoint, OneDrive for Business, Microsoft Purview, Defender XDR, Copilot, and Universal Print. Full recovery took roughly 48 hours, with a handful of services still limping days later.
Timeline
- ~5:30 PM UTC, Aug 31 — Microsoft opens incident EX1464935, acknowledging Exchange Online problems after a spike in user reports.
- Early afternoon EDT — Microsoft points to a core authentication configuration problem affecting multiple internal services within the Exchange Online infrastructure.
- Mid-afternoon EDT — The incident is escalated to a broader tracking number, MO1465074, as impact spreads well beyond email into Teams, Microsoft Graph, Purview, OneDrive for Business, SharePoint Online, the admin center, Copilot, Universal Print, and Defender XDR.
- Evening, Aug 31 — Microsoft says it has identified the faulty authentication component and is testing a fix on a slice of infrastructure before rolling it out more broadly.
- Sept 1 — Microsoft reports positive recovery trends roughly 22 hours in; core Exchange mail flow and search come back online first.
- Sept 2, ~12:41 PM EDT — About 48 hours after the start, Microsoft says everything has recovered except Exchange Online, Universal Print, OneDrive for Business, and SharePoint Online, which were still trailing behind.
At peak, Downdetector logged tens of thousands of reports for Outlook and Microsoft 365 combined.
Cause of the Outage
Microsoft’s official line, repeated across its status updates, never got more specific than pointing to a core authentication configuration problem affecting multiple Microsoft 365 services. That’s a deliberately vague description, and Microsoft did not publicly confirm a more precise mechanism in the days following the incident.
That vagueness left room for speculation. The most persistent theory, seeded by an admin’s error message referencing an expired certificate thumbprint and picked up by several outlets, was that a certificate Microsoft was supposed to renew had lapsed. Microsoft never confirmed this. It’s a plausible theory, Microsoft has had genuine expired-certificate outages before (a Teams outage in 2020 was officially attributed to one), but as of the most recent updates, “core authentication configuration” is the only cause Microsoft has put its name to.
Why it spread so far
Exchange, Teams, SharePoint, OneDrive, and Defender all sit on the same underlying Microsoft 365 identity/authentication layer. When that shared layer degrades, it doesn’t just take down email, it takes down everything bolted onto it. That’s the trade-off of a unified identity system: efficient when healthy, a single point of failure when it isn’t.
The takeaway
This wasn’t a cyberattack, Microsoft was explicit that this was a service availability issue, not a security incident. It was an internal authentication component failing (or being misconfigured) in a way that cascaded across nearly every major Microsoft 365 workload, and it took Microsoft about two full days to fully unwind. For IT teams, the practical lesson is familiar: have a fallback communication channel that doesn’t depend on Microsoft 365 itself, because when the auth layer goes down, so does the tool you’d normally use to coordinate the response.
Note: Microsoft has not published a formal post-incident review (PIR) with a definitive root cause as of this writing. Details may be updated as Microsoft releases more information.
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.