Exchange Online Mailbox Quarantine Issue

Overview

Microsoft is investigating and working to resolve an ongoing Exchange Online incident (EX1436407) that has mistakenly quarantined customer mailboxes since July 19, 2026. The issue has disrupted email delivery, calendar access, and overall productivity for affected users, highlighting the fragility of cloud‑based collaboration systems when infrastructure changes go wrong.

Root Cause

Microsoft linked the problem to a recent infrastructure change that caused excessive memory consumption.

  • This led to an out‑of‑memory condition, which incorrectly triggered mailbox quarantines.
  • As a result:
    • Users could not receive emails.
    • Senders received Non‑Delivery Reports (NDRs).
    • Calendars became inaccessible for quarantined accounts.

Microsoft noted this is a recurrence of a previous issue (EX1434354), requiring additional remediation steps for full restoration.

Current Status

  • Cleanup of excess indexing data is ongoing.
  • Progress has moved from 66% complete on Wednesday afternoon to 72% complete by Wednesday evening.
  • Mailboxes are gradually being removed from quarantine as memory levels are validated region by region.
  • Microsoft has not yet provided a completion timeline, promising updates in future communications.

Historical Context

Exchange Online has faced similar incidents in recent years:

  • March 2025 — Anti‑spam systems mistakenly quarantined legitimate emails.
  • May 2025 — Gmail messages incorrectly flagged as spam due to a faulty machine learning model.
  • September 2025 — Anti‑spam service blocked URLs and quarantined emails across Exchange Online and Teams.
  • February 2026 — Heuristic detection rules misclassified thousands of legitimate URLs as phishing links, quarantining valid emails.

These repeated issues highlight the complexity of automated detection systems and the risks of infrastructure changes at scale.

Recommendations for Admins

While awaiting Microsoft’s full remediation, IT administrators should:

  • Monitor Service Health Dashboard for incident updates.
  • Communicate with end users about potential delays and NDRs.
  • Review quarantined mailboxes to confirm which accounts are impacted.
  • Prepare contingency workflows for critical communications.

Expert in the Cloud Insight

This incident underscores the operational risks of cloud dependency. Even minor infrastructure changes can cascade into widespread service disruptions. For enterprises, the lesson is clear: maintain visibility, prepare fallback communication channels, and treat cloud service health monitoring as a critical IT function.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.