Microsoft is investigating a Microsoft 365 Copilot availability incident tracked as CP1470554. Affected users may be unable to open Copilot or may receive errors while accessing or interacting with the service, including through Copilot-integrated Microsoft 365 applications.
Microsoft had not disclosed the root cause, affected regions, or an estimated recovery time. The company has not identified the incident as a breach or cyberattack; tenant administrators should monitor the Microsoft 365 admin center Service Health Dashboard and avoid unnecessary endpoint, credential, or client-configuration changes while the cloud-service disruption remains active.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft began investigating CP1470554, an availability incident in which users may be unable to open Microsoft 365 Copilot or encounter errors interacting with it, including through Microsoft 365 integrations. The company had not disclosed a root cause, affected regions, or recovery estimate and directed administrators to the Service Health Dashboard.
Microsoft reported mitigating a separate issue affecting access to Microsoft Copilot on the web on September 10.
Microsoft restored Copilot Chat after a configuration change on September 5 caused some queries to return a “Something went wrong” error.
A late-August Microsoft 365 outage tied to a core authentication configuration caused Copilot prompts requiring Microsoft 365 grounding, including email content, to fail.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.