Microsoft 365 Alert – Service Degradation – Exchange Online – Users may be unable to connect to, or experience degraded functionality with Exchange Online – RESOLVED
01/09/2026 08:51:00 AM
NHS.net Connect Reference: INC46923137
Microsoft Reference: EX1464935
Issue Status: RESOLVED
Issue Description: Users may be unable to connect to, or experience degraded functionality with Exchange Online.
More info: Microsoft has confirmed that the authentication component issue impacted other services beyond Exchange Online. For more information regarding other impact scenarios, please see: MO1465074.
They have opted to keep this post (EX1464935) open as Exchange Online was the most predominantly impacted service.
Users may have experienced a variety of symptoms related to this event, including but not limited to:
– Users couldn’t download email message attachments through any Exchange Online connection method.
– Delays, failures, or incomplete results when searching for content within Exchange Online mailboxes.
– Delays or failures when sending or receiving email messages.
– Authentication-related errors when accessing Exchange Online services.
– Difficulties accessing or performing actions within Exchange administration experiences.
– Intermittent failures affecting mailbox operations and message delivery work.
– Delays or failures when sending or receiving email messages via Outlook for iOS and Android.
– Users may have been unable to use room finder in Outlook calendars.
– Users may have been unable to sign in to Outlook on the web.
Final Update: 04/09/2026 10:27:00 AM – Based on Microsoft’s telemetry all previously impacted services have remained healthy since impact was remediated on Thursday, September 3, 2026, at 10:00 AM UTC, and this issue is resolved.
Scope of impact: Users attempting to perform any of the outlined impact scenarios may be affected by this event.
Root cause: An issue within a core authentication configuration used by multiple Microsoft 365 services was resulting in impact.
Next steps: Microsoft is evaluating their core authentication configurations to prevent the recurrence of similar impact in the future. In addition, they are further reviewing their monitoring systems to ensure they identify and are expediently alerted to these types of scenarios.
They will provide a preliminary Post-Incident Report within two business days and a final Post-Incident Report within five business days.