# Microsoft 365 Outage Cripples Teams, SharePoint, and Copilot Chat Across North America


## The Threat


On the morning of July 23, 2026, Microsoft's 365 suite began falling apart. Starting at 10:44 AM ET, users across North America found themselves locked out of or degraded across nearly every major Microsoft cloud service — Teams, SharePoint, OneDrive, Power Automate, Microsoft Loop, Copilot Chat, and the Admin Center itself. This wasn't a phishing campaign or a ransomware incident. It was a foundational infrastructure failure, and for a few hours, the tooling that millions of organizations depend on for day-to-day operations simply didn't work.


By 11:11 AM ET, Downdetector had recorded 2,403 user reports — roughly 80 times the normal baseline of 29. SharePoint dominated the complaints at 78%, followed by Excel at 11% and the Microsoft 365 Admin Center at 6%. That Admin Center degradation is worth paying attention to: when the tool administrators use to diagnose and respond to problems is itself unavailable, the outage compounds. IT teams were flying partly blind.


Microsoft's initial traffic rerouting offered partial relief for some users, but early mitigation attempts failed to hold. The company issued a blunt advisory warning customers to review their business continuity and disaster recovery plans — a rare public admission that the timeline was unknown and the fallback was on them. By 1:55 PM ET, Microsoft indicated it may have identified the root cause and was deploying mitigations, with a promised update within 30 minutes. As of this writing, the situation remains a developing story.


## Severity and Impact


This is an outage event, not a CVE-tracked vulnerability. Impact is measured in service availability and organizational disruption.


| Metric | Detail |

|--------|--------|

| Incident ID | MO1437424 |

| Outage Start | 10:44 AM ET, July 23, 2026 |

| Peak Reports (Downdetector) | 2,403 (vs. baseline of 29) |

| Geographic Scope | North America (primary) |

| Root Cause | Network path degradation — likely cause identified by 1:55 PM ET |

| Mitigation Status | Partial recovery; full resolution ETA not confirmed |

| Services Confirmed Degraded | 7 (Teams, SharePoint, OneDrive, Admin Center, Power Automate, Copilot Chat, Loop) |


## Affected Products


The following Microsoft 365 services experienced confirmed degradation:


  • SharePoint Online — "Something went wrong" errors; heaviest volume of user reports (78% of Downdetector complaints)
  • Microsoft OneDrive — Intermittent access failures
  • Microsoft Teams — Degraded chat functionality; images not loading for many users
  • Microsoft 365 Admin Center — Slow to load or completely inaccessible
  • Power Automate — Automate flows not loading
  • Copilot Chat — Intermittent delays and failures on actions and queries
  • Microsoft Loop — Pages unable to open or load

  • Users accessing Microsoft 365 via certain network paths in North America appear most affected. Organizations with global infrastructure may have seen partial service via alternate routing.


    ## Mitigations


    Microsoft's guidance and recommended organizational responses during the outage:


  • Monitor the Admin Center — Track incident MO1437424 in the Microsoft 365 Admin Center for live status updates from Microsoft's engineering team, understanding that the Admin Center itself may load slowly.
  • Activate business continuity plans — Microsoft explicitly asked customers to review and act on their BCDR (Business Continuity and Disaster Recovery) plans. Organizations without tested fallbacks for Teams or SharePoint should treat this outage as a fire drill.
  • Use alternate communication channels — For Teams outages, have pre-established backups: email, SMS bridges, or alternate platforms like Slack or Google Meet. Don't assume Teams will always be available.
  • Delay critical automated workflows — Power Automate flows that failed silently during this outage may require manual review and re-triggering once services recover. Audit automation logs post-incident.
  • Watch for phishing follow-on — Major outages create social engineering windows. Threat actors send fake "Microsoft 365 recovery" emails within hours of high-visibility incidents. Brief your users now.
  • Document the impact window — For SLA and contractual purposes, log which services were inaccessible and for how long. Microsoft's Service Level Agreement remediation process requires incident documentation.

  • ## References


  • Microsoft 365 Status — Admin Center incident MO1437424
  • [Microsoft Service Health Dashboard](https://admin.microsoft.com/)
  • [Downdetector — Microsoft 365 live reports](https://downdetector.com/status/microsoft-365/)
  • Original reporting via BleepingComputer, July 23, 2026

  • ---


    ## HackWire Analysis


    The real story here isn't that Microsoft had an outage — large cloud platforms fail. The story is the Admin Center going down alongside everything else.


    When an outage takes out the monitoring and incident response tooling simultaneously, it reveals a concentration risk that organizations consistently underestimate. Administrators couldn't check Microsoft's own service health dashboard efficiently, couldn't run diagnostics, and in some cases couldn't communicate internally through Teams to coordinate a response — all because the failure lived in the same infrastructure stack. That's not redundancy. That's a single point of failure wearing seven different hats.


    Microsoft's warning to customers to "review business continuity and disaster recovery plans" is technically correct advice, but it's arriving mid-outage, which is too late to be useful. BCDR plans need to be tested and operational before the platform goes down. Most enterprises haven't done tabletop exercises that model a complete Microsoft 365 collapse because the mental model is that cloud providers are more resilient than on-premises infrastructure. Some days they are. Today they weren't.


    The timing also matters. This hit mid-morning Eastern — peak business hours for North American enterprises. Finance teams running month-end Excel workflows, operations staff coordinating through Teams, developers triggering Power Automate pipelines. The blast radius of a 10:44 AM outage is substantially larger than a 2 AM one.


    For defenders and IT leads: the follow-on phishing risk is real and often overlooked. Within 24 hours of major Microsoft outages, threat actors deploy credential-harvesting campaigns disguised as Microsoft account recovery notices. Brief your users today, before the fake emails land.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)