Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptioncloud-service-vulnerability

Microsoft Azure Outage Caused by Configuration Error

Updated 3mo agoFirst seen Oct 30, 20252 sources

Microsoft Azure and 365 services experienced a significant outage due to an inadvertent configuration change, resulting in widespread latencies, timeouts, and errors for users. The disruption affected a broad range of Azure services, including App Service, Azure Active Directory B2C, Azure Communication Services, Azure Databricks, Azure Healthcare APIs, Azure Maps, Azure Portal, Azure SQL Database, Container Registry, Media Services, Microsoft Defender External Attack Surface Management, Microsoft Entra ID, Microsoft Purview, Microsoft Sentinel, Video Indexer, and Virtual Desktop. Microsoft responded by deploying its last known good configuration and began recovering nodes and re-routing traffic through healthy nodes, though some users continued to experience intermittent failures during the recovery process.

The outage occurred just hours before Microsoft's quarterly earnings call and followed a similar cloud DNS error that had disrupted AWS users the previous week. Microsoft communicated the incident and recovery status via its Azure Status page, stating that full recovery was expected by the evening. The incident highlights the operational risks associated with cloud infrastructure and the potential for configuration errors to cause widespread service disruptions across critical business applications.

Share:
Microsoft Azure Outage Caused by Configuration Error
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Oct 29, 20258mo ago

Microsoft restores Azure Front Door using last known good configuration

Microsoft said it restored Azure Front Door by deploying a last known good configuration following the outage. The company then gradually recovered nodes and rebalanced traffic to avoid instability and overload as dependent services came back online.

Microsoft configuration change triggers Azure and Microsoft 365 outage

Around noon on October 29, 2025, Microsoft suffered an outage affecting Azure and Microsoft 365 after an inadvertent configuration change caused latencies, timeouts, and errors. Impacted services included Azure Front Door, App Service, Azure SQL Database, Azure Portal, Microsoft Entra ID, and Microsoft Sentinel.

Oct 20, 20258mo ago

AWS DNS misconfiguration causes major outage in Northern Virginia

Amazon Web Services experienced a major outage attributed to a DNS misconfiguration that affected DynamoDB API endpoint resolution in the Northern Virginia region. The disruption impacted AWS services and numerous customers, including UK banks, government websites, and consumer services such as Disney+, Venmo, and Signal.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

21 LINKEDOpen in app
Affected products
7 linked
Azure Virtual DesktopSignalAzure Active Directory B2cAmazon Web ServicesAzure PortalAzure Container RegistryMicrosoft Entra Id
Organizations
14 linked
Amazon Web ServicesThe Walt Disney CompanyLloyds Banking GroupRingPayPalMicrosoft CorporationSignal MessengerHalifaxAmazonHM Revenue and CustomsGov.UkDisney+McDonald'sVenmo
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.