Office 365 Outage Map
The map below depicts the most recent cities worldwide where Office 365 users have reported problems and outages. If you are having an issue with Office 365, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Office 365 users affected:
Office 365 is an online productivity suite that is developed by Microsoft. Office 365 contains online and offline versions of Microsoft Office, Skype and Onedrive, as well as online versions of Sharepoint, Exchange and Project.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Bogotá, Bogota D.C. | 2 |
| Paris, Île-de-France | 1 |
| Milly-la-Forêt, Île-de-France | 1 |
| Unión de Crédito Agrícola de Hermosillo, SON | 1 |
| Mumbai, MH | 1 |
| Antiguo Cuscatlán, La Libertad | 1 |
| La Rochelle, Nouvelle-Aquitaine | 1 |
| Nice, Provence-Alpes-Côte d'Azur | 1 |
| Reims, ACAL | 1 |
| Dreux, Centre | 1 |
| Merlimont, Hauts-de-France | 1 |
| Puteaux, Île-de-France | 1 |
| Valence, Auvergne-Rhône-Alpes | 1 |
| Marseille, Provence-Alpes-Côte d'Azur | 2 |
| Saint-Malo, Brittany | 1 |
| Saint-Denis, Réunion | 1 |
| Réunion, Réunion | 1 |
| Saint-Paul, Réunion | 1 |
| Melbourne, VIC | 3 |
| Montpellier, Occitanie | 1 |
| Redruth, England | 1 |
| Cheltenham, England | 1 |
| Tewkesbury, England | 1 |
| Edmonton, AB | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Office 365 Issues Reports
Latest outage, problems and issue reports in social media:
-
Breck Yunits (@breckyunits) reported@Trace_Cohen The long tail uses of AI are enormous. There are so many things that open self-hosted models enable that are off the table with centralized controlled models. Think of *nix on satellites, rather than them phoning Redmond for a license renewal, as an illustrative example. I already see a higher exponential growth in brains investing in open models than frontier models. Similar to how when I worked at Microsoft, the best were all using *nix and *** at home. It will only hang on to the frontier if it can government capture. Now that's a huge possibility, perhaps even greater than 50%. I mean Microsoft's software is terrible, (Windows, Azure, Office 365), and yet crushes it because of gov capture. It would be financially reckless to short without accurately modeling that risk. But in a free market, open >> closed.
-
Occasional Opiner (@OccasionalOpie) reported@jimcramer $MSFT has now gone red. AI must be chowing down on Windows and Office 365.
-
Shadow Mann (@ShadowMann9) reported@BadalK99277 No. Windows is only still relevant because of entrenchment. Active Directory, Windows Server, Office365, Azure, all are relevant only because of entrenchment. If all software that only runs on Windows could run on Linux, then there would be no need for Windows.
-
HectorE (@HectorE88315654) reported@BrianRoemmele And now they’re blocking the installation of Claude extension for their Office 365 products, there are reported issues this weekend of problems with this, I tried to install it and it marked an error , and investigating online I saw many users reported this issue.
-
Jonathan Cantliff (@cantliff9) reported@madebygoogle @MicrosoftHelps @gmail Gmail app not working with Office 365 emails (again) Doesn't seem to want to load modern authentication Could someone look into this please Widespread complaints online and on app store reviews. Folks, this needs some attention!
-
Microsoft Threat Intelligence (@MsftSecIntel) reportedMicrosoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.
-
Maik Voets (@MaikVoets) reported@ariaradnia Only if you move from a Google workspace company to one that’s all choked up in office 365 you realize how bad their products are. Take collaboration in their office products. They still often have synchronization issues - these are the basics! Why can’t they figure it out?
-
Lalith Kumar V (@lalitvlk) reported@AmazonHelp Please refund my money. Your Amazon team is not at all helping me regarding this issue. They are asking me to search the brand (office 365) in google and contact them. Amazon has sold a fake product. It’s your duty to refund me .
-
Daniel (@dan325) reported@nonlinear_james @atalocke I’m using it to manage my work office 365 email right now without any issue. Not IMAP, either. It has native exchange capabilities. Also, WTF is wrong with IMAP? Evolution’s biggest advantage is it doesn’t tether me to a proprietary OS. No copilot BS on my computer!
-
DFIR Radar (@DFIR_Radar) reportedSilk Typhoon (HAFNIUM), a Chinese 🇨🇳 state APT, has evolved from on-prem Exchange exploitation to cloud-native supply chain attacks, most recently abusing CVE-2025-3928 in Commvault's Azure-hosted M365 backup SaaS to pivot into downstream customer tenants. - Initial access spans three vectors: CVE-2025-3928 (zero-day in Commvault Web Server, T1190), stolen API keys from privileged cloud vendors (T1195), and leaked corporate credentials found on public repos like GitHub (T1078.004). The Commvault campaign gave them client secrets for Metallic M365 backups, opening direct paths into customer M365 environments via hijacked service principals. - Lateral movement pivots from on-prem to cloud by targeting Entra Connect servers (T1210, T1078.002), enabling privilege sync between Active Directory and Entra ID. Credential dumping and key vault theft support pass-the-hash moves (T1550.002) into Azure. - Persistence relies on adding passwords to existing consented service principals or creating new Entra ID applications named to mimic legitimate Office 365 services (T1098.001, T1036). Web shells handle C2 on compromised Azure VMs (T1505.003). - Collection targets email via EWS and MSGraph APIs, plus SharePoint (T1213.002) and OneDrive (T1213.003), all through OAuth apps with admin consent, a low-noise, API-native exfiltration path that bypasses many endpoint controls. #DFIR_Radar
-
Daniel Heithorn ➡️ Xbox Gamescom (@DanielHeithorn) reported@WindowsCentral Because...consumer. No human support option on first contact. Only AI, Forums & Forms. Automated responses. It's the same issue as consumer Office 365 user. If you run in a serious problem as data loss or exchange issues, you're screwed. Only commercial customer get a minimum
-
Sambath (@sambath47) reported@SayNoToTrading MSFT- Massive AI capex is weighing on the stock FCF is significantly down It’s AI push in office 365 and copilot are not generating needle moving revenues Let’s see if the chips can move the stock!! But still a high quality stock to buy
-
Ed Andersen (@edandersen) reported@matvelloso Yes their attach rate to office 365 is not great but the entire company is behind it. It’s not being wound down
-
Nick (@maietta) reported@paul_e_jones No, I have zero business with GoDaddy. But I have to deal with them for an issue that they caused through Microsoft office 365's design. The problem is that a domain name that belongs to my client used to belong to a company that used to have a Microsoft office 365 account provided through the vendor. GoDaddy. GoDaddy sells office 365 accounts. What happens is a domain name previously used with Microsoft office 365 but then the account expires and is never renewed because the company that held the domain name went out of business and sold in bankruptcy. Two company transitions later and we acquire the domain. So we go to set up Microsoft office 365 only to be hit with a message that we cannot provision the domain on their platform because of a previous tenant that just doesn't exist anymore in the real world. That business vanished a long time ago.
-
Gabriel Lawson (@glawsontweets) reportedAgentic troubleshooting report: Tricky office 365 installation issue due to, unbeknownst to me, an unmounted drive. Claude code with Opus 4.7 max tried for an hour, failed to find cause. Codex with gpt 5.5 xhigh found cause and fixed the issue in 10 minutes!