Microsoft Addresses Exchange Online Mailbox Quarantine Issue
Microsoft is addressing an ongoing Exchange Online problem that has led to unauthorized mailbox quarantines for users since July 19.
Root Cause Identified
The issue, designated as EX1436407, remains unresolved as of the latest update on Wednesday. Affected users have reported disruptions in email functionality, including inability to send or receive messages and access calendar data. The root cause has been identified as a recent infrastructure modification that triggered excessive memory usage, resulting in an out-of-memory condition that incorrectly isolated impacted mailboxes.
Infrastructure Modification
The company explained that the anomaly stems from unexpected indexing data generating high memory consumption, which triggered the quarantine process. This has caused some users to be blocked from receiving emails, with senders encountering Non-delivery Reports (NDRs). Microsoft highlighted that this situation mirrors a prior incident, EX1434354, requiring additional corrective actions for full resolution.
Cleanup Initiative
A cleanup initiative targeting the excess indexing data has advanced steadily, progressing from 66% completion on Wednesday afternoon to 72% by Wednesday evening. As part of this effort, mailboxes are being gradually released from quarantine as memory metrics are validated across different geographic areas. Microsoft has not yet provided a definitive timeline for full recovery but indicated it would share updates in an upcoming report. The next status update is scheduled for 6 p.m. UTC later today.
Past Exchange Online Disruptions
This incident follows a series of past Exchange Online disruptions involving improper email quarantine or classification. In March 2025, an anti-spam system flaw caused legitimate emails to be mistakenly isolated. A separate issue in May 2025 saw machine learning models incorrectly flagging Gmail-originated messages as spam. In September, an anti-spam service malfunction blocked URL access for Exchange Online and Microsoft Teams users while quarantining emails. Earlier in February, faulty heuristic rules designed to combat credential phishing campaigns incorrectly marked thousands of valid URLs as phishing links.
Security Teams’ Insights
Security teams report that 54% of successful attacks go undetected, with only 14% triggering alerts. Tools like breach and attack simulation help validate detection systems to reduce blind spots.
Microsoft’s Response
Microsoft continues to investigate the current issue while emphasizing the importance of rigorous testing for security layers to prevent similar incidents.
