Microsoft 365 outage enters second day as search disruptions persist Microsoft is working to resolve a widespread Microsoft 365 outage that has entered its second day, with search and other functions across Exchange Online, SharePoint, OneDrive, Teams, and Microsoft 365 Copilot still affected despite the recovery of much of the Exchange Online mail flow. The incident began at 11:55 a.m. UTC on August 31, with Microsoft attributing the root cause to an issue within a core authentication configuration used by multiple Microsoft 365 services. Microsoft has not provided an estimated time for full resolution. Microsoft is working to resolve a widespread Microsoft 365 disruption that has entered its second day, with search and other functions across Exchange Online, SharePoint, OneDrive, Teams and Microsoft 365 Copilot still affected despite the recovery of much of the Exchange Online mail flow. The incident, according to a report https://mailservices.isc.upenn.edu/computing/email/penno365/alerts/ms-incidents.html published by the University of Pennsylvania’s IT department based on data from Microsoft’s admin console, began with Microsoft investigating an increase in user reports of Exchange Online problems at 11:55 a.m. UTC on August 31. By 12:33 p.m. UTC, Microsoft said it had isolated a common failure pattern across affected Exchange Online requests associated with authentication and protocol connectivity, and was working on potential remediation options. About an hour later, it said that a potential corrective action for the affected infrastructure had been identified and the nature of its deployment was being evaluated. However, another hour later, it reported that the problem had extended beyond Exchange Online to other Microsoft 365 services, but stopped short of calling it a complete or total outage. Instead, it listed https://status.cloud.microsoft/ a range of degraded or failed functions across services, including Exchange Online connectivity and search, SharePoint Online and OneDrive for Business search, file access, synchronization and content loading, Teams search, calendars and presence, and Microsoft 365 Copilot prompts requiring Microsoft 365 data. A few minutes later, it listed 3:08 p.m. UTC as the official start time of that broader incident and soon attributed the root cause to “an issue within a core authentication configuration used by multiple Microsoft 365 services.” Microsoft then spent the next few hours testing how to restore the affected authentication components and determine why they were not being deployed as expected. At 4:36 p.m. UTC, the hyperscaler said it was re-examining recent changes and exploring ways to safely restore the components, including potentially reverting an update received by affected infrastructure. By 5:55 p.m. UTC, Microsoft said mitigation testing had produced positive results and that it was continuing to test and implement strategies to apply the necessary authentication component. Later at 6:40 p.m. UTC, the hyperscaler began implementing a targeted mitigation to reapply core authentication components across a sample of affected infrastructure while reporting that some users were beginning to see recovery in certain impacted scenarios and that it would incrementally expand the mitigation. Microsoft subsequently expanded the mitigation and began restarting targeted sections of infrastructure. The recovery was not uniform for all affected enterprise customers immediately. While Microsoft, by late Monday, was reporting widespread recovery of Exchange Online mail connectivity, it warned that some organizations could take longer to drain backlogged mail queues. The company subsequently said it had validated persistent recovery of mail flow across the environment and shifted its focus to restoring search functionality. That partial recovery did not, however, bring the broader incident to an end. Microsoft continued working on search-related issues into Tuesday, restarting affected infrastructure and reapplying the targeted authentication-component fix across affected environments. In its latest update at 2:39 a.m. UTC, the company said those efforts had “yielded progress,” with incremental improvement in service-health telemetry associated with search functionality across a sample of the affected environment. It is still continuing the remediation across additional sections of infrastructure but the hyperscaler has not provided an estimated time for full resolution. It has said that it would provide an estimated recovery timeline when one becomes available, leaving the duration of the disruption uncertain as the incident enters its second day. That for enterprises could delay routine business workflows and leave employees without access to critical information and tools until services are fully restored.