Office 365 status: access issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Office 365 is an online productivity suite that is developed by Microsoft. Office 365 contains online and offline versions of Microsoft Office, Skype and Onedrive, as well as online versions of Sharepoint, Exchange and Project.
Problems in the last 24 hours
The graph below depicts the number of Office 365 reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Office 365. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Office 365 users through our website.
- Sign in (66%)
- Website Down (20%)
- Errors (14%)
Live Outage Map
The most recent Office 365 outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Sign in | 2 days ago |
|
|
Website Down | 8 days ago |
|
|
Website Down | 9 days ago |
|
|
Website Down | 10 days ago |
|
|
Sign in | 10 days ago |
|
|
Sign in | 12 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Office 365 Issues Reports
Latest outage, problems and issue reports in social media:
-
userlolxxl (@userlolxxl) reported@medsci_yb3r @MicrosoftLearn @Microsoft Tenant😬overcomming 'problems' to sign-out edu-Office 365, a new private Office licence is running, other licence associated with edu-office(.)com says 'Connection failure'. .. but, I can use edu-licence Office 365 again, after a year of non-functional licence. Chaos? Reality.
-
Carlod (@justcarlod) reported@peach2k2 @B1rtek1 Same. You have to go to office 365 logout and then sign in again. This is inhumane UX!
-
Microsoft Threat Intelligence (@MsftSecIntel) reportedMicrosoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.
-
The Paprika Elf Video Store (@PEVideoStore) reported@billypurgatory I'm still salty about the fact that I bought Office 2016 where they advertised it as a lifetime product and now they announced they will stop supporting it. I'm still using it because I refuse to pay for Office 365. It's just crazy how terrible of a company Microsoft has become.
-
Usama Mansuri (@usama_mansuri90) reported@Outlook @gmail Dear Support Team, I am experiencing an issue while configuring my Gmail account on Microsoft Office 365. This account is already successfully configured and working on five devices. However, I am unable to configure it on a sixth device. During the setup process, I receive an error message. Please note that our company email domain is hosted with Google. I kindly request your assistance in resolving this issue. Please let me know if you require any additional information, including screenshots of the error message. Thank you for your support.
-
Brian Murray (@intheblueyonder) reported@_stormed @xPraveen07 I used to agree, but at this point, IT is just factory farming. Nobody knows what they’re doing, so if they can just use remote office 365 and basic tools, that’s what IT departments hire. I had one guy quit because “they use Linux on a server”. Ok buddy, don’t let the door hit you on the way out.
-
chris (@xH4ngEm) reportedThere's a question I get asked constantly by investors building individual accounts: how much of a single name is too much? Been sitting with this in the context of the Revere Gro and Rair exposure framework circulating around $MSFT positions. The model tries to map concentration risk across growth-rate sensitivity and rate-cycle sensitivity - not a bad starting structure. But I think it locates the problem slightly wrong. For a long-horizon value investor, risk management is not primarily about volatility. It's about permanent capital impairment. Those are genuinely different things, and conflating them leads to genuinely different mistakes. MSFT at current prices trades around 32-33x forward earnings. P/B north of 13. EV/EBITDA in the high 20s depending on the quarter. Not cheap multiples by historical standards - even for a business generating the FCF that Microsoft does. And the FCF is real: Azure margin expansion, Office 365 recurring, Activision slowly integrating. The capital allocation story holds up - disciplined buybacks, a growing dividend, R&D spend that's actually productive rather than defensive. ROIC consistently above cost of capital. The moat is not in question. But here's the thing about exposure management in individual accounts specifically: when you hold a concentrated position in a company priced for near-perfection, your margin of safety becomes structural rather than mathematical. You can't just point at the balance sheet and call it hedged. The Rair framing - rate-adjusted intrinsic return - is useful because it forces the right question: if the 10-year rises another 100bps from here, does this company's intrinsic value hold? For MSFT, probably yes. The business doesn't need cheap debt to function. It generates cash in almost any macro environment. The moat doesn't erode with rates. But position sizing is where individual investors chronically underperform. Institutions manage downside scenarios as a daily operational function. Individual investors size based on conviction - and conviction is not risk management. Conviction is the justification for taking risk. Risk management is the system of rules that governs how much risk you actually accept. Practical framework, after holding through multiple cycles: - If you can articulate the bear case (multiple compression, Azure growth deceleration, AI capex overhang not yet reflected in FCF) and still sleep at night at 10-12% allocation, that's probably the rational ceiling for a concentrated individual book. - If a 20% drawdown in this one name would materially alter your financial situation, you've crossed from investing into speculating on management quality and multiple expansion. The Revere Gro side of the concept is really just another way of saying: don't let a great company become a great risk by virtue of how much of your book it occupies. The business quality and the position size are separate questions that individual investors routinely collapse into one. Balance sheet analysis matters. FCF trajectory matters. They're inputs into a position-sizing decision - not substitutes for one. That distinction is the actual heart of risk management in individual accounts, and most frameworks bury it. Long MSFT. Have been for years. Never let it exceed 12% of the book regardless of how strongly I believe in the thesis. That ceiling is a feature.
-
Virtually Fun (@virtuallyfun) reported@tomhounsell @Chris123NT I'm kinda surprised that office365 still lets me host my domain and forward to my exchange server. But it's still a PITA some services just plain refuse to send to MSFT for no reason (Amazon 3fa) but I get all their ****** Amazon ads ..
-
Bɛrima Yaw Poku 🧠👁️👂🏾 (@barimayawpoku) reported@elliot_solution Ah, na government communications and emails koraa are running on office365 na documents. They don’t even have on-premise exchange communication server managed in house for data control and security seff. Tweaaa
-
WhiskeySilverball (@WhiskeySlvrBall) reported@Pirat_Nation I assume this is related to the issue that caused Office 365 email to collapse worldwide earlier this week.
-
Lalith Kumar V (@lalitvlk) reported@AmazonHelp Please refund my money. Your Amazon team is not at all helping me regarding this issue. They are asking me to search the brand (office 365) in google and contact them. Amazon has sold a fake product. It’s your duty to refund me .
-
PS5 “ RUNS ON XBOX GAMES” (@DomingoRoldan1) reported@AmericanTimdog @Grummz Just do steam,the problems it’s contents creator, staying quite and going to June show. We need to stop supporting content creators . Bring the whole house down. Am not subscribing to no office 365 , going full with google Gemini..I have GP till 2027 am done.
-
Tag VinZant (@TagVinZant) reportedI wonder how much productivity the entire world economy has lost just from Microsoft products not working as intended. Freelancing for a new company, and they gave me my first Office 365 email that I've ever had to deal with on a professional basis. Within the first 2 hours, it's not even working and won't let me send emails. I'll take "things that would never happen with Gmail" for $500.
-
Security Weekly Podcast Network (@SecWeekly) reportedPasswords get stolen. MFA prompts get approved. Rob Allen explains why some organizations are now locking SaaS apps like Office 365, GitHub, and Salesforce to specific trusted IP paths instead of exposing login access to the entire internet. Even if an attacker has credentials, they still can’t connect unless traffic comes from the approved location. Is location-based access control becoming the next layer after MFA? #Cybersecurity #SaaS #IdentitySecurity
-
Eric Sauvageau (@RMerlinDev) reported@Diss0lution For many years now, the Office 365 installer is broken in French, instead of showing something like "90% complété" in the system notification icon, it says "90lformat error! complété" - incorrectly parsing the percent sign as a parameter. Trillon dollars company at work.
-
The 5th Estate (@The_5thEstate) reported@clnuponaisle5 Most cloud services let you upload encrypted data to. I use OneDrive because the Office 365 subscription gives 1tb of storage space and integrates with the Windows OS really well. I encrypt my files before uploading and it has no problems.
-
Breck Yunits (@breckyunits) reported@Trace_Cohen The long tail uses of AI are enormous. There are so many things that open self-hosted models enable that are off the table with centralized controlled models. Think of *nix on satellites, rather than them phoning Redmond for a license renewal, as an illustrative example. I already see a higher exponential growth in brains investing in open models than frontier models. Similar to how when I worked at Microsoft, the best were all using *nix and *** at home. It will only hang on to the frontier if it can government capture. Now that's a huge possibility, perhaps even greater than 50%. I mean Microsoft's software is terrible, (Windows, Azure, Office 365), and yet crushes it because of gov capture. It would be financially reckless to short without accurately modeling that risk. But in a free market, open >> closed.
-
Rob (@Rob_Tb_West) reported@NXT4EU We used to have office computers, running on an office server park. No outside computers had access. Micro$oft mandates Office 365 and OneDrive. The server may be in Europe, but where is the backup server. And more important: Who has admin rights over your files?
-
Maik Voets (@MaikVoets) reported@ariaradnia Only if you move from a Google workspace company to one that’s all choked up in office 365 you realize how bad their products are. Take collaboration in their office products. They still often have synchronization issues - these are the basics! Why can’t they figure it out?
-
Mike Nicoletti (@mikenicoletti) reportedThe bear case on Office 365 boils down to one thing: does Microsoft participate in the agent-facing side of data work? Right now most people talk to agents through a terminal or some stitched-together texting setup. If Microsoft makes Teams the place you talk to your agents and share work with them, they own the interface. That interface is the moat.
-
Dan (@Holmyverse) reported@FinanceDirCFO But rather "subprime AI", right? SaaS stocks go down because people don't get business, and think that Dropbox, LinkedIn, Spotify, Office 365, Slack, Netflix, Instagram etc. will go out of business simply because "anyone can vibe code their own version".
-
Aaron Matthew Kaiser (@aaronkaiser) reportedI am really disappointed in @Apple Business. They finally launch a cloud platform for business mail, but you can’t set up a user mailbox if it was previously used in iCloud+ custom email domains?? I’m being told that it’s not just a 30 day wait, I will never be able to set those mailboxes up. And there’s no user aliases, no multi-domain email support. No multi-tenant offerings (not that I expect that yet). I get that it’s still in its infancy, but come on. These are basic features and they worked with the personal side. I found a way to create user groups with emails that seemed like a workaround to still get mail that’s addressed to these inboxes, but then I found out that they can only be emailed to internally from the same domain. Apple policies are blocking external senders. I spoke to four different support reps over 3+ hours yesterday and they don’t even understand this issue or how to fix it. They keep asking about where the domain is registered when it is clearly an issue deep within Apple systems at a very high level that needs to be changed. I didn’t like the Office 365 integration with the Apple ecosystem, which is why I was so excited for this. But not having access to my mailboxes and not even being able to implement a workaround IS A MAJOR ISSUE. What’s going on @tim_cook? How could this have shipped like this?
-
Matt Talley (@tallemd) reportedOffice 365 has been priced at $6 per inbox for over a decade and during that time it has never turned a profit. I'm almost sure that means it's impossible. Normally you would shut down an unprofitable line of business but the military insists it is necessary for war effort.
-
Pythis (@Pythis1313) reported@darknesss932 An attorney should request a server level search utilizing Microsoft Purview ediscovery. I would wager they are using office365 for email which means that a query kql could be created pertinent to the case executed on the entire tenant for the time frames involved.
-
🌍🌳🐟🙉Ady🤔 (@AdyG28) reported@YTJustGetATesla My current gripe is Microsoft Office 365 which i have to use at work for shared documents, its slow as f., can even grind to a halt when just adding a row to a excel sheet. I use libreoffice when doing anything that isnt onedrive shared.
-
DFIR Radar (@DFIR_Radar) reportedSilk Typhoon (HAFNIUM), a Chinese 🇨🇳 state APT, has evolved from on-prem Exchange exploitation to cloud-native supply chain attacks, most recently abusing CVE-2025-3928 in Commvault's Azure-hosted M365 backup SaaS to pivot into downstream customer tenants. - Initial access spans three vectors: CVE-2025-3928 (zero-day in Commvault Web Server, T1190), stolen API keys from privileged cloud vendors (T1195), and leaked corporate credentials found on public repos like GitHub (T1078.004). The Commvault campaign gave them client secrets for Metallic M365 backups, opening direct paths into customer M365 environments via hijacked service principals. - Lateral movement pivots from on-prem to cloud by targeting Entra Connect servers (T1210, T1078.002), enabling privilege sync between Active Directory and Entra ID. Credential dumping and key vault theft support pass-the-hash moves (T1550.002) into Azure. - Persistence relies on adding passwords to existing consented service principals or creating new Entra ID applications named to mimic legitimate Office 365 services (T1098.001, T1036). Web shells handle C2 on compromised Azure VMs (T1505.003). - Collection targets email via EWS and MSGraph APIs, plus SharePoint (T1213.002) and OneDrive (T1213.003), all through OAuth apps with admin consent, a low-noise, API-native exfiltration path that bypasses many endpoint controls. #DFIR_Radar
-
David Miller (@Dav4Usa) reportedEmail down all over today for Office 365
-
AD (@AD1991234) reported@signulll I used to think MSFT was oversold, but I now think they have a major issue. Office 365 is not agent friendly, the OS is from a different era. Teams is a disgrace.
-
Occasional Opiner (@OccasionalOpie) reported@jimcramer $MSFT has now gone red. AI must be chowing down on Windows and Office 365.
-
Cockatrice (@kimtaikennedy) reportedJust login to entra dashboard portal as office365 admin and delete all MFAs there and login back to email easy