Cyber Security News

Microsoft Attributes Recent Microsoft 365 Outage to Authentication Token Failure

Microsoft confirmed a significant outage affecting its Microsoft 365 suite on March 3, 2025, linking the disruption to a critical failure in its authentication token system.

The incident, which impacted users across Canada and parts of the U.S. for nearly three hours, prevented access to Outlook, Teams, and OneDrive.

Authentication tokens, which validate user identities without requiring repeated logins, failed to renew automatically due to unresponsive regional servers.

This triggered a large amount of authentication errors, locking users out of cloud-based applications. Microsoft’s Incident MO1022159 noted the problem originated in Canada, where routing issues with local ISPs like Rogers exacerbated the outage.

Administrators temporarily mitigated the issue by clearing cached tokens or restarting the Click-to-Run service—a stopgap solution discussed in Reddit threads.

While Microsoft assured users no data was compromised, the outage highlighted dependencies on centralized authentication systems without fallback protocols.

Services resumed fully by 2:20 AM, but the outage underscores cloud infrastructure’s vulnerability to authentication bottlenecks.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago