Update (July 24): Microsoft has completed its preliminary investigation and said the widespread Microsoft 365 outage was caused by a bug in its automated network maintenance request system, not a confirmed cyberattack. According to the company, the bug mistakenly removed IP routes from more network devices than intended during routine maintenance in its West US Azure region, disrupting connectivity for Microsoft 365 and Azure services. Microsoft also said it has found no evidence that malicious activity caused the outage.
Microsoft is investigating a widespread outage impacting multiple Microsoft 365 services after users across North America reported issues accessing SharePoint Online, Microsoft Teams, OneDrive, Excel, Power Automate, the Microsoft 365 Admin Center, and other cloud services.
The incident, tracked by Microsoft as MO1437424, began on July 23, with thousands of users reporting service disruptions. Downdetector recorded a sharp increase in outage reports, with SharePoint accounting for the majority of complaints as organizations experienced errors, slow performance, and intermittent connectivity issues. Microsoft acknowledged the incident and said engineers were investigating service telemetry and diagnostic data to determine the source of the disruption.
Services impacted
According to Microsoft’s service health updates, the outage affected multiple Microsoft 365 workloads, including:
- SharePoint Online
- Microsoft Teams
- OneDrive
- Power Automate
- Microsoft 365 Admin Center
- Copilot Chat
- Microsoft Loop
Users reported issues ranging from “Something went wrong” errors in SharePoint to degraded Teams functionality, missing images in chats, intermittent OneDrive access, and slow or unavailable administrative portals.
Microsoft begins mitigation
As the outage progressed, Microsoft said it was scaling traffic rerouting efforts and implementing mitigation measures after identifying a networking-related issue affecting service availability. Later updates indicated that a networking change had been reverted and telemetry suggested services were beginning to recover while engineers continued monitoring the environment and validating restoration with affected customers.
Hacktivist group claimed responsibility
During the outage, the hacktivist group known as 313 Team, also known as the Islamic Cyber Resistance in Iraq, published Telegram posts claiming responsibility for a distributed denial-of-service (DDoS) attack targeting Microsoft’s SharePoint infrastructure. The posts included screenshots of Downdetector outage reports and asserted that multiple Microsoft 365 services had been disrupted.
Microsoft has since released a preliminary post-incident review attributing the outage to an internal networking error during routine maintenance. According to the company, a bug in its automated maintenance request system incorrectly removed IP routes from additional network devices, disrupting traffic between its West US Azure region and Microsoft’s wide-area network.
Microsoft has not identified any evidence that the outage resulted from a cyberattack. As a result, there is currently no independent evidence supporting 313 Team’s claim of responsibility.

Microsoft publishes preliminary findings
Microsoft said the outage began at 10:44 a.m. ET on July 23 after a routine maintenance request incorrectly removed network routes from more infrastructure than intended. Engineers traced the issue to Microsoft’s West US Azure region and rolled back the networking change beginning at 1:45 p.m. ET, completing the rollback at 2:26 p.m. ET.
The company said service telemetry confirmed recovery after the rollback, with affected Microsoft 365 and Azure services returning to normal later that afternoon. Microsoft is conducting a full post-incident review and said it plans to publish a final root cause analysis after completing its internal investigation.











