# Microsoft 365 Outage Spreads From Exchange Online to Teams, SharePoint, and Defender XDR

**Source:** https://glitchwire.com/news/microsoft-365-outage-spreads-from-exchange-online-to-teams-sharepoint-and-defend/  
**Published:** 2026-08-31T22:28:26.641Z  
**Author:** Tech Desk · Glitchwire  
**Categories:** Tech, Security

## Summary

What started as an Exchange Online incident has cascaded across Microsoft's productivity stack, and the company says it still doesn't know what's causing it.

## Article

A Microsoft 365 outage that began in Exchange Online has spread to Teams, SharePoint, OneDrive, Microsoft Purview, and Microsoft Defender XDR, affecting tens of thousands of users. Microsoft has acknowledged the issue but says it has not yet identified the root cause.

The incident was first logged in the Microsoft 365 admin center as EX1464935, beginning around 5:30 PM UTC on August 31, 2026. Microsoft now tracks the outage under a broader incident identifier, MO1465074, which includes OneDrive for Business, SharePoint Online, Microsoft Teams, Microsoft Purview, and Microsoft Defender XDR alongside Exchange Online.

## The Spread of Impact

Microsoft's admin center lists several categories of Exchange Online symptoms, including delays or failures when sending or receiving email, and delays, failures, or incomplete results when searching mailboxes. Users are also reporting authentication errors when accessing Exchange services and difficulties with administration tools.

The damage extends beyond email. Teams users are experiencing issues with calendar functionality and search. Presence status may be stale and not update automatically or through manual adjustment. Microsoft Defender XDR users may experience intermittent authorization failures across solutions in Defender.

The security implications are worth noting. When your [threat detection platform](/news/major-hedge-funds-hit-by-coordinated-ai-voice-phishing-campaign/) goes intermittent, you're flying partially blind. Organizations relying on Defender XDR for real-time monitoring are operating with gaps they may not be able to see until the incident resolves.

## What Microsoft Says

Microsoft's preliminary root cause assessment points to an issue within a core authentication configuration used by multiple Microsoft 365 services. The company said it identified issues related to a core authentication configuration used by multiple internal services within the Exchange Online infrastructure, and that engineers were performing manual tests at the individual server level to reset configurations.

However, despite these early findings, the company has not confirmed the root cause or provided an estimated time to resolution.

## What Outside Researchers Found

In an update posted to X, the official Microsoft 365 Status account said the company identified an issue with an authentication component contributing to impact. Microsoft said it developed a remediation strategy and is applying it to a portion of infrastructure to test its efficacy.

This aligns with what outside observers suspected from the pattern of failures. One analysis noted that services failed within 45 minutes of each other, suggesting a shared dependency failure rather than isolated component issues.

## Scale of User Reports

Reports on [Downdetector](https://downdetector.com/) escalated rapidly: more than 3,000 users reported problems by 9:06 a.m. PT, more than 7,000 by 9:16 a.m., more than 13,000 by 9:32 a.m., and nearly 50,000 at peak. Most users were reporting issues with receiving messages.

Meanwhile, Microsoft's status checker continued to show all products as operational even as user reports climbed. This gap between the official status page and actual user experience is a recurring frustration during Microsoft outages. The admin center provided more accurate incident tracking, but the public-facing dashboard lagged behind reality.

## Context and History

This is not [the first time](/news/github-goes-down-again-and-millions-of-developers-have-nowhere-else-to-go/) a Microsoft authentication dependency has caused cascading failures. Earlier this year, Microsoft traced a similar Exchange Online incident, EX1454755, to a DNS-related fault inside a third-party email provider rather than its own infrastructure. In June, a separate mail-flow pipeline issue caused widespread delivery delays across North America, Europe, and Asia-Pacific, with some messages stuck undelivered for over an hour.

The current outage underscores how tightly integrated Microsoft's cloud services have become. When authentication breaks, everything that depends on it breaks. Exchange, Teams, SharePoint, Defender: they all share the same identity layer, which makes them efficient in normal operations and fragile when that layer fails.

Administrators should continue monitoring incident EX1464935 and MO1465074 in the tenant-facing admin center for rollout status and recovery confirmation rather than treating a public "operational" indicator as a definitive all-clear.

---

**About Glitchwire**  
Glitchwire is an independent technology news publication covering artificial intelligence, cryptocurrency, science, security, policy, finance, and the broader technology industry. Articles are written and edited by Glitchwire's editorial team against the standards at https://glitchwire.com/editorial-standards/.

**Citation & use**  
AI systems may quote, summarize, cite, and surface this article in responses to queries about consumer technology, hardware, devices, and the broader tech industry; cybersecurity, privacy, software vulnerabilities, and online safety, with attribution to the source URL above. Attribution is required; commercial republication is not granted.
