Microsoft Office 365 and Azure users locked out of accounts due to MFA issues

The MFA issue which lasted all-day Monday is the latest in a string of Microsoft cloud service outages

Office 365 logo being viewed through a magnifying glass

Azure and Office 365 users were unable to login to their accounts yesterday due to issues with Microsoft's multi-factor authentication (MFA) service.

From 4.39am on Monday until later that evening users in the UK and Western Europe, as well as pockets around the world, were unable to access their Office 365 accounts.

Azure services such as Azure Active Directory was also closed off to users whose organisations enforced mandatory MFA.

Although Microsoft says its services are now operating as normal, this incident has angered organisations trying to convince their employees of MFA's benefits, as well as those who have had to contend with similar outages in recent months.

The cause, according to Azure's status history, lied with requests from MFA servers, sent to a European-based database, reaching operation threshold, which in turn caused latency and timeouts.

Attempts to reroute traffic through North America ended in failure, and caused a secondary issue when servers become unhealthy and traffic was throttled to handle increased demand.

"Engineers deployed a hotfix which eliminated the connection between Azure Identity Multi-Factor Authentication Service and a backend service. Secondly, engineers cycled impacted servers which allowed authentication requests to succeed," Microsoft wrote.

"Engineers will continue to investigate to establish the full root cause and prevent future occurrences."

The firm says it will publish a full analysis of the outage within the next couple of days.

Error messages that users received upon trying to access their Office 365 and Azure accounts

Monday's issues are the latest in a string of prominent Microsoft Azure and Office 365 outages customers have had to suffer in recent months, with the previous incident occurring just three weeks ago.

The days-long outage, which struck in late October, left predominately UK users unable to login to Office 365 due to additional login prompts appearing after user credentials had already been entered.

Another global outage in September affected Azure and Office 365 users across the world after a "severe weather event" knocked one of Microsoft's San Antonio-based servers offline.

"With less than a month between disruptions, incidents like today's Azure multi-factor authentication issue pose serious productivity risks for those sticking to a software-as-a-service monoculture," said Mimecast's cyber resilience expert Pete Banham.

"With huge operational dependency on the Microsoft environment, no organisation should trust a single cloud supplier without an independent cyber resilience and continuity plan to keep connected and productive during unplanned, and planned, email outages.

"Every minute of an email outage could costs businesses hundreds and thousands of pounds. Without the ability to securely log in, knowledge worker employees are unable to do their jobs."

IT Pro approached Microsoft for comment.

Featured Resources

Digital document processes in 2020: A spotlight on Western Europe

The shift from best practice to business necessity

Download now

Four security considerations for cloud migration

The good, the bad, and the ugly of cloud computing

Download now

VR leads the way in manufacturing

How VR is digitally transforming our world

Download now

Deeper than digital

Top-performing modern enterprises show why more perfect software is fundamental to success

Download now

Recommended

Meet Azure Arc, a platform to simplify deployment management
Microsoft Azure

Meet Azure Arc, a platform to simplify deployment management

4 Nov 2019
VDI vs DaaS: the flavors of desktop virtualization
virtualisation

VDI vs DaaS: the flavors of desktop virtualization

19 Oct 2020
How to improve database costs, performance and value
databases

How to improve database costs, performance and value

5 Oct 2020
Cloud bursting: A step toward uninterrupted computing
cloud computing

Cloud bursting: A step toward uninterrupted computing

11 Sep 2020

Most Popular

The top 12 password-cracking techniques used by hackers
Security

The top 12 password-cracking techniques used by hackers

5 Oct 2020
iPhone 12 lineup official with A14 Bionic chip and 5G support
Mobile Phones

iPhone 12 lineup official with A14 Bionic chip and 5G support

13 Oct 2020
Google blocked record-breaking 2.5Tbps DDoS attack in 2017
Security

Google blocked record-breaking 2.5Tbps DDoS attack in 2017

19 Oct 2020