Microsoft confirmed a Microsoft 365 service-degradation incident, tracked as MO1472904, after users worldwide reported being unable to access core applications and receiving HTTP 502 and 503 errors. The disruption began at approximately 7:17 PM GMT+5:30 on September 16.
Microsoft engineering teams are reviewing telemetry and customer reports to identify the affected fault domain, root cause, and remediation; no recovery timeline or attack attribution was available. Administrators should monitor the Microsoft 365 admin center for updates and avoid unnecessary password resets or configuration changes while the investigation continues.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed service-degradation incident MO1472904 after users worldwide lost access to core Microsoft 365 applications and encountered HTTP 502 and 503 errors. Engineering teams began reviewing telemetry and customer reports; no root cause, resolution timeline, or connection to prior incidents had been identified.
Exchange Online experienced a multi-day authentication failure.
A networking misconfiguration disrupted Microsoft Teams and SharePoint services in North America.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.