The images in this article were generated with artificial intelligence. How we publish
Microsoft is investigating a persistent problem in Exchange Online that for weeks has caused intermittent access to mailboxes from Outlook mobile applications and from the new Outlook client for macOS. According to the communiqués published at the management message centre, the company initially detected a change in infrastructure - related to the introduction of a virtual account - as a possible source, marked the incidence as resolved in early April and soon thereafter reopened the follow-up under another identifier to continue the investigation. You can check the official notifications at the Microsoft management center in the notices EX1256020 and EX1268771.
In its most recent updates, the Exchange Online team indicate that one of the ongoing measures is to restart the service called Notification Broker in the affected infrastructure parts to mitigate impact while continuing with a deeper analysis of the root cause. This type of rebeginning is a common containment action.: allow to recover delivery or synchronization capacity in the short term while investigating why the component failed or generated unexpected behavior.

Microsoft has described the effect as intermittent, which complicates both the detection and the quantification of the actual reach. The company has not published precise public details about affected regions or the number of users affected by these weeks of problems, which is common when communications are managed mainly from the management message centre. If you want to better understand how and where Microsoft publishes this type of ad, its documentation on the status of the service and the message center is available in the official help: Service health in Microsoft 365 and the message center for administrators.
This incident is in addition to a succession of recent setbacks in Exchange Online services that have affected different protocols and customers in recent months: early this month there was an interruption that prevented access to mailboxes and calendars from Outlook on the web, Desktop Outlook, Exchange ActiveSync and other protocols, and also solved login problems related to Office.com and Copilot web capabilities. Other previous episodes included intermittent interruptions in IMAP4 and synchronization problems with classic Outlook customers. The frequency of these incidents underlines the operational complexity of maintaining a global cloud mail and synchronization service especially when multiple versions of customers and protocols coexist with continuous changes in the platform.
For IT administrators and managers, the situation raises a number of practical concerns: intermittent nature makes reproduction and diagnosis difficult, and the lack of public detail on scope may complicate communication to end users. As Microsoft advances in research, the usual recommendations include monitoring the message center and the status panel (for managers) and, if appropriate, opening a Microsoft support case to accelerate attention when the problem affects critical operations. Official documentation on incident management and how to scale problems is available in Microsoft 365 resources mentioned above.

If you are a user affected by mail access problems on mobile Outlook or in the new Outlook for Mac, there are temporary measures that are often useful: try to access through Outlook on the web (OWA) to confirm that the mailbox is operational from another route, update the applications to the latest version, and in specific cases delete and add the account to the client. These actions do not solve the underlying cause in the cloud service, but can reduce the impact while Microsoft applies the corrections.
Beyond the technical steps, this episode recalls that even large suppliers can have regressions by introducing changes in global services and that transparency on scope and progress in resolution is vital for managers and users to plan responses. Maintaining local copies of critical data, designing continuity plans that consider temporary degradation and using multiple access channels (web, mobile and alternative desktop client) are practices that reduce operational vulnerability to such incidents.
I will be attentive to new updates from the Online Exchange team and Microsoft message center; if you want, I can follow the thread and let you know when there is a statement that details the root cause or exact reach of the affected users and regions. As sources for real-time verification, see Microsoft 365 status panel and the corresponding entries in the Microsoft management center whose reference appears at the beginning of this article.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...