Full Report
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
Analysis Summary
# Incident Report: Exchange Online Service Disruption (EX1467029)
## Executive Summary
Microsoft Exchange Online experienced a significant service disruption characterized by "Server busy" errors and substantial delays for emails sent to and received from external domains. The issue was exacerbated by automated anti-spam protections triggered during the event. Microsoft is currently investigating the root cause and reviewing service telemetry to mitigate the impact.
## Incident Details
- **Discovery Date:** September 4, 2026, 02:19 AM EDT
- **Incident Date:** September 4, 2026
- **Affected Organization:** Microsoft (Exchange Online)
- **Sector:** Information Technology / Cloud Services
- **Geography:** Global (Regional specifics pending, though previous similar incidents impacted North America, APAC, and Europe)
## Timeline of Events
### Initial Access
- **Date/Time:** September 4, 2026 (Early morning hours)
- **Vector:** N/A (Likely Infrastructure/Configuration failure; no evidence of malicious attack reported)
- **Details:** Users began reporting intermittent "Server busy" errors when attempting to communicate with external domains.
### Lateral Movement
- **Details:** Not applicable; the incident appears to be a service-wide infrastructure degradation rather than a security breach involving lateral movement.
### Data Exfiltration/Impact
- **Details:** No data exfiltration reported. Impact is limited to service availability and mail flow integrity (delays and delivery failures).
### Detection & Response
- **Discovery:** Detected via service telemetry and user reports of intermittent errors.
- **Response Actions:** Microsoft opened incident EX1467029, initiated a review of service logs, and identified that anti-spam protections were contributing to the delays for a subset of users.
## Attack Methodology
*Note: Current telemetry indicates a service outage/reliability issue rather than a cyberattack. The following fields are based on the reported technical behavior of the outage.*
- **Initial Access:** N/A
- **Persistence:** N/A
- **Privilege Escalation:** N/A
- **Defense Evasion:** N/A
- **Credential Access:** N/A
- **Discovery:** N/A
- **Lateral Movement:** N/A
- **Collection:** N/A
- **Exfiltration:** N/A
- **Impact:** Service Disruption; Resource exhaustion (intermittent "Server busy" errors).
## Impact Assessment
- **Financial:** Potential SLA (Service Level Agreement) credit claims from enterprise customers; productivity loss for impacted organizations.
- **Data Breach:** None reported.
- **Operational:** High; disruption of external business communications and delayed mail flow.
- **Reputational:** Moderate; follows a series of recent Microsoft 365 outages in the same year (April and June 2026).
## Indicators of Compromise
- **Network indicators:** Intermittent "Server busy" responses from Exchange Online SMTP/API endpoints.
- **File indicators:** N/A
- **Behavioral indicators:** Backlog in mail queues; aggressive throttling by anti-spam filters on legitimate outbound/inbound external mail.
## Response Actions
- **Containment measures:** Ongoing analysis of anti-spam protection behavior to prevent further unnecessary throttling.
- **Eradication steps:** Microsoft is reviewing service telemetry to identify the underlying infrastructure bottleneck.
- **Recovery actions:** Automated re-routing of traffic and potential adjustment of spam filter thresholds to clear mail backlogs.
## Lessons Learned
- **Key takeaways:** Automated security features (like anti-spam protections) can inadvertently worsen service outages by misidentifying traffic surges or errors as malicious activity.
- **What could have been done better:** Investigation is ongoing; however, the frequency of similar outages (April, June, and September) suggests a need for more robust regression testing for infrastructure updates.
## Recommendations
- **Prevention measures:**
- Implement more granular "fail-safe" modes for anti-spam systems that can distinguish between infrastructure errors and actual spam campaigns.
- Organizations should maintain secondary communication channels (e.g., Teams, Slack, or backup mail providers) to ensure business continuity during Exchange outages.
- Monitor Microsoft 365 Service Health Dashboard (admin[.]cloud[.]microsoft) for updates on incident EX1467029.