Microsoft has reported a significant service disruption impacting its Microsoft 365 suite, affecting users around the globe. The problem began on the evening of September 16, 2026, leading to widespread reports of users being unable to access essential applications.
Error Codes and Service Impact
The issue, internally identified as MO1472904, commenced at 7:17 PM GMT+5:30. Microsoft has termed it as a service degradation, not a complete outage, yet it has already provoked numerous complaints from both business and personal account holders.
According to a Microsoft advisory, users are encountering 502 and 503 HTTP errors when trying to access Microsoft 365 services. These error codes usually indicate server overload, gateway timeouts, or upstream infrastructure problems, differing from issues related to user authentication or credentials.
Ongoing Investigations and Updates
As of the latest update at 7:36 PM GMT+5:30, Microsoft’s engineering team is examining service data and user reports to pinpoint the cause and devise a solution. The company plans to provide another update by 3:30 PM UTC, although the resolution timeline is still uncertain.
Microsoft 365 Status on Twitter also acknowledged the issue, directing users to the admin center for more details under MO1472904.
Context and Historical Challenges
This disruption is part of a challenging period for Microsoft’s cloud services, which experienced several outages in 2026, such as a prolonged Exchange Online issue in August and a July network misconfiguration affecting Teams and SharePoint in North America.
Previous incidents were linked to authentication failures and network errors, but it remains unclear if MO1472904 shares these causes.
For IT administrators, monitoring the Microsoft 365 admin center for detailed impact information is crucial, as 502 and 503 errors may affect different tenants or regions in varying ways.
Future Considerations
Organizations facing disruptions should refrain from unnecessary password changes or configuration modifications until Microsoft provides clarity, as such actions have historically complicated recovery efforts. Security teams need to differentiate between actual service degradation and potential denial-of-service attacks, as error codes alone do not exclude malicious activity.
Cyber Security News will continue to track MO1472904 and provide updates as Microsoft releases further information on resolving this incident.
