Microsoft reported multiple service-impacting incidents across its cloud ecosystem. Administrators in North America and Canada experienced an outage and degraded performance in the Microsoft 365 admin center, with some users also unable to access the M365 app or raise support tickets; Microsoft said it was analyzing telemetry, usage patterns, and CPU utilization, and reviewing user-provided HAR files to isolate the root cause.
Separately, Exchange Online quarantined legitimate messages after an updated URL rule incorrectly marked some URLs as phishing, disrupting email flow for affected customers while Microsoft worked to release quarantined mail and unblock legitimate URLs. In another disruption, Microsoft attributed Windows Update and Microsoft Store failures/timeouts (notably impacting Windows 11 users) to a utility power interruption at a West US datacenter, which cascaded into issues with Azure storage clusters supporting content delivery; backup power engaged and power was later stabilized, but service recovery required additional remediation beyond restoring electricity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
As the Microsoft 365 admin center incident continued, Microsoft analyzed telemetry, CPU utilization, usage patterns, and HAR files from affected users to isolate the cause. At the time of reporting, the company had not identified a confirmed root cause and suggested workarounds such as Microsoft Graph API or legacy admin portals for urgent tasks.
Microsoft published the North America admin center disruption on its service health dashboard as Issue ID MO1230320. The company said telemetry showed intermittent authentication endpoint and admin portal API failures, with users seeing HTTP 5xx errors, long load times, and session timeouts.
On 2026-02-10, Microsoft began investigating a service degradation preventing some business and enterprise administrators in North America from accessing the Microsoft 365 admin center. Affected users also reported degraded functionality in the admin portal and M365 app, including problems raising support tickets.
Microsoft later confirmed the Exchange Online false positives were caused by an updated URL rule that mistakenly marked some legitimate URLs as malicious. The company began releasing quarantined messages and unblocking affected URLs as mitigation.
By 2026-02-08, Microsoft said most services affected by the West US datacenter outage were back online, though residual latency was expected while storage consistency checks completed. The company advised users to retry later and told administrators to consult Azure Service Health for tenant-specific status.
Microsoft said backup power systems activated and utility power was stabilized after the West US outage, but recovery was prolonged by cold-start and re-synchronization requirements for Azure storage services. The incident also degraded telemetry pipelines, causing monitoring and log delays for some Azure resources.
Around 08:00 UTC on 2026-02-07, a power outage at a Microsoft West US datacenter caused widespread disruption affecting Azure-dependent services, including Microsoft Store and Windows Update. Windows 11 users were unable to download apps or complete updates, and Azure customers saw timeouts and failures.
After the email filtering issue began, Microsoft publicly acknowledged the Exchange Online incident in a service alert and said evolving anti-phishing criteria and URL-based detections were involved. The company classified it as an incident with noticeable user impact.
Microsoft said an Exchange Online incident started on 2026-02-05, causing legitimate emails to be incorrectly flagged as phishing and quarantined. The issue disrupted customers' ability to send and receive email.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.