Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptioncloud-service-vulnerability

Microsoft Azure and Microsoft 365 Global Outage Due to DNS Issues

Updated 3mo agoFirst seen Oct 29, 20259 sources

Microsoft experienced a widespread outage impacting Azure, Microsoft 365, and related services, affecting customers and organizations worldwide. The disruption began around 16:00 UTC and was attributed to DNS issues, resulting in degraded availability for services such as Azure Front Door, the Azure Portal, Intune, Exchange admin center, and authentication services. Major companies and sectors, including payroll providers, healthcare organizations, and the Dutch railway system, reported significant operational impacts, with users unable to log in or access critical business platforms. Microsoft acknowledged the outage, provided mitigation advice such as using programmatic access methods and failover strategies, but did not immediately offer an estimated time for resolution.

The outage's effects were felt across a broad spectrum of industries, with reports of internal workflow disruptions and delays in essential services like payroll processing. Microsoft advised customers to consider implementing failover strategies using Azure Traffic Manager and to monitor the Azure status page for updates. The incident highlighted the critical dependency of global businesses on Microsoft's cloud infrastructure and the cascading impact of DNS-related failures on authentication and service availability.

Share:
Microsoft Azure and Microsoft 365 Global Outage Due to DNS Issues
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 30, 20258mo ago

Lingering intermittent issues continue into October 30

After the main outage was declared over, some users and services continued to experience residual or intermittent problems into 2025-10-30. Follow-up reporting noted that while the major disruption had ended, not all effects had fully cleared immediately.

Oct 29, 20258mo ago

Most Microsoft services gradually recover, with full recovery expected later that evening

Late on 2025-10-29, Microsoft said service health was improving and estimated recovery by 23:20 UTC. Most affected Azure and Microsoft 365 services were gradually restored by the end of the day, though some instability remained.

Microsoft says rollback completed and recovery is underway

By about 5:30 p.m. ET on 2025-10-29, Microsoft reported that rollback deployment had completed. The company said it was recovering nodes and rerouting traffic, while warning users to expect intermittent failures during restoration.

Outage causes downstream disruptions for third parties and customer websites

As the incident unfolded on 2025-10-29, organizations and services dependent on Microsoft infrastructure reported knock-on effects, including issues affecting Alaska Airlines, Vodafone UK, Heathrow Airport, and Azure-hosted customer websites. Reports also described broader internet-facing disruption involving services such as Zoom, Starbucks, and Capital One.

Microsoft identifies suspected configuration change and starts rollback

During the outage on 2025-10-29, Microsoft said it suspected an inadvertent configuration change had triggered the incident. The company blocked further customer configuration changes and began rolling back to a last known good configuration while rerouting traffic and recovering nodes.

Microsoft outage begins, disrupting Azure Front Door and DNS-dependent services

On 2025-10-29, a global Microsoft outage began around 11:40 a.m. to noon ET, affecting Azure Front Door availability and causing DNS-related failures. The disruption impacted Azure-hosted applications and major Microsoft services including Microsoft 365, Teams, Entra, Xbox Live, Minecraft, Outlook, and LinkedIn.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Affected products
9 linked
Amazon Web ServicesAzure Front DoorAzure Virtual DesktopAzure Active Directory B2cAzure PortalAzure Container RegistryLinkedinMicrosoft Entra IdXbox
Organizations
10 linked
Microsoft CorporationAmazon Web ServicesAlaska AirlinesVodafoneStarbucksZDNETCostco Wholesale CorporationHeathrow AirportDowndetectorOokla
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.