Microsoft working to fix Exchange Online mailbox quarantine issue

A major issue is unfolding for Microsoft’s Exchange Online users, with thousands of mailboxes mistakenly quarantined since Sunday. The problem, which has been ongoing for four days, has left users unable to receive and send emails, access their calendars, or even send emails to those whose mailboxes are incorrectly marked as quarantined.

At the heart of this issue is a recent infrastructure change made by Microsoft, which inadvertently caused excessive memory consumption in Exchange Online. This led to an out-of-memory condition that mistakenly flagged some users’ mailboxes for quarantine, effectively blocking their ability to receive emails and causing sending emails to these accounts to result in Non-delivery Reports (NDRs).

This is not the first time such a problem has occurred. A similar issue was reported just last year, when Microsoft’s anti-spam systems mistakenly quarantined some users’ emails due to faulty heuristic detection rules designed to block credential phishing campaigns. On that occasion, thousands of legitimate URLs were incorrectly flagged as phishing links.

Microsoft has acknowledged the current issue and is working to resolve it as quickly as possible. An ongoing cleanup process aimed at removing excess indexing data from Exchange Online has been steadily progressing over the past few days, with 72% completion reported by Wednesday evening. However, the company has not provided a timeline for when the full remediation will be completed.

The fact that this issue is affecting thousands of users makes it a significant concern for Microsoft, especially given its previous experiences with similar problems. The company’s failure to prevent such incidents highlights the ongoing challenges in maintaining the security and reliability of complex cloud services like Exchange Online. In an era where cybersecurity threats are becoming increasingly sophisticated, companies must remain vigilant and proactive in identifying potential issues before they become major incidents.

In this case, Microsoft’s efforts to resolve the issue are being closely monitored by affected users and security professionals alike. As we wait for a resolution, it serves as a reminder of the importance of robust testing and validation processes in preventing similar issues from occurring in the future.


Source: Bleeping Computer — 2026-07-23