An outage that began across Microsoft 365 on August 31 was still unresolved the following day. Mail flow came back first, but search in Exchange Online, SharePoint, OneDrive and Teams stayed unreliable for far longer, and some Microsoft 365 Copilot responses stopped working. Microsoft pointed to a fault in an authentication configuration shared by several services.

One Authentication Configuration Pulled Multiple Services Down

It started with mail. At around 11:55 UTC on August 31, Microsoft noticed a rise in user reports about Exchange Online and opened an investigation. Roughly 40 minutes later it said it had isolated a common failure pattern across the affected requests, tied to authentication and protocol connectivity.

While remediation options were still being weighed, the impact spread beyond Exchange Online. Microsoft logged 15:08 UTC as the official start of the wider incident and described the root cause as a problem within a core authentication configuration used by multiple Microsoft 365 services. The Exchange Online problem was first tracked as EX1464935, then folded into a broader incident, MO1465074, covering SharePoint Online, OneDrive for Business, Teams, Microsoft Purview and Microsoft Defender XDR.

The list of broken functions shows how far the fault reached. Exchange Online lost connectivity and search. SharePoint Online and OneDrive for Business lost file access, synchronization, content loading and search. Teams lost search, calendars and presence. Microsoft 365 Copilot failed on prompts that needed to read Microsoft 365 data. To users these look like separate applications, but underneath they were leaning on the same authentication plumbing.

Mail Recovered First, Search Took the Longest

Recovery came in stages. Around 16:36 UTC, Microsoft said it was re-examining recent changes and looking for a safe way to restore the authentication components, including the possibility of reverting an update. About an hour later it reported positive results from mitigation testing, and by roughly 18:40 UTC it had begun reapplying the authentication components to a targeted sample of infrastructure, expanding the fix as it confirmed results and restarting affected sections along the way.

Different services came back at different speeds. Exchange Online mail connectivity was largely restored by late Monday, though Microsoft cautioned that some organizations would need extra time to drain backlogged mail queues. Once it confirmed that mail flow recovery was holding, it shifted focus to search.

Search recovery ran past midnight. In an update at 02:39 UTC on September 1, the company said the work had produced incremental improvement in service health telemetry for search across a sample of the affected environment, with no estimated time for full resolution. Microsoft later reported that mail flow and search had been restored. Counting from the first reports, the incident took close to a full day.

Copilot Added a New Place Where Failure Hurts

One detail stands out: Microsoft 365 Copilot appeared on the impact list. A generative AI assistant looks like something that works as long as the model is running. But an assistant aimed at internal work is only useful once it can read mail, files, meetings and chat. If the data layer or the authentication layer goes down, a perfectly healthy model still has nothing to answer with.

The more work companies hand to AI agents, the heavier that dependency becomes. An outage that used to mean "mail is down" or "files won't open" starts to mean that the system doing the work has stopped as well. When designing for redundancy, it is worth checking whether authentication and the path to data have become a single point of failure, before worrying about model availability.

Practical Precautions Worth Keeping in Mind

There is only so much a customer can do, but not nothing. During authentication failures, already signed-in sessions often survive, while devices forced to re-authenticate are the first to lose access. Signing out or changing a password in the middle of an incident can leave a user locked out until the service recovers.

The other point is communication. When Teams and Exchange Online fail together, internal contact routes disappear at the same time. Keeping a primary incident channel on a separate system preserves at least the ability to share status and give instructions. Service health information in the Microsoft admin center can itself depend on the same tenant authentication, so an external status page is a useful second source.

Summary

The Microsoft 365 outage that began on August 31 stemmed from a fault in an authentication configuration shared by multiple services, and it spread from Exchange Online to SharePoint, OneDrive, Teams and Microsoft 365 Copilot. Mail flow largely returned the same day, while search recovery stretched into September 1. The incident is a reminder of how much a single shared component carries, and of the fact that AI assistants now sit on top of it.

Note: the thumbnail image is AI-generated.