A Certificate Expired. Microsoft 365 Went Down for Two Days.
On August 31, 2026, an expired certificate inside a core Microsoft 365 authentication component (thumbprint 19F04B8A233DD9CE916F118056D224A1751729EA) cascaded into Exchange Online, Teams, SharePoint, OneDrive, Purview, Defender XDR, Copilot, and Universal Print. Tracked initially as EX1464935 and escalated to MO1465074, the outage took roughly two days to substantially resolve, with Exchange Online, Universal Print, OneDrive for Business, and SharePoint Online still degraded as late as September 2. There was no attacker and no novel bug: a scheduled, calendar-predictable credential expiration went unmonitored on infrastructure Microsoft fully controls, and the shared authentication path it broke cascaded the failure to every service that trusted it.
This was not a customer-side patch validation failure; it was a monitoring and drift-detection gap on Microsoft's own infrastructure. Nothing was deployed on August 31: a certificate that had been valid for months quietly crossed a scheduled, years-known expiration date, and no automated expiry monitoring caught it before that deadline arrived. Because Exchange Online, Teams, SharePoint, OneDrive, Purview, Defender XDR, Copilot, and Universal Print all depend on the same authentication path, a single expired credential cascaded across all of them simultaneously. Detection was fast, the same day impact began, but the rest of those roughly two days went to remediation: reapplying authentication components across a large, distributed footprint of infrastructure, because no verified, uniformly-deployable known-good fallback existed to roll back to.