Microsoft working to fix Exchange Online mailbox quarantine issue

Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday.
The incident, tracked by Microsoft under EX1436407, began on July 19 and remained unresolved as of the most recent update Wednesday evening. During this time, affected Exchange Online users have been experiencing issues receiving and sending emails and accessing their calendars.
Microsoft has linked the problem to a recent infrastructure change that caused excessive memory consumption, resulting in an out-of-memory condition that triggered the incorrect mailbox quarantines.
“This issue may block some users from receiving email messages due to their mailboxes incorrectly being quarantined, and users sending email to these mailboxes may receive a Non-delivery Report (NDR),” Microsoft said.
“A recent infrastructure change caused excessive memory consumption from unexpected indexing data results in an out-of-memory condition, causing affected mailboxes to be incorrectly quarantined.”
Microsoft also noted that this is a recurrence of a previous issue, tracked as EX1434354, and that additional remediation steps were needed for full restoration.
While the company has yet to disclose which regions are impacted by this ongoing issue or how many customers are affected, it has classified it as an incident, which usually involves noticeable user impact.
An ongoing cleanup of the excess indexing data has progressed steadily, going from 66% complete as of Wednesday afternoon to 72% complete by Wednesday evening, with mailboxes gradually being removed from quarantine to expedite recovery as memory levels are validated in different regions.
Microsoft has yet to provide a completion timeline for full remediation, saying only that it would provide one in a future update. The company’s next update on the incident is scheduled for later today, at 6 p.m. UTC.
Over the last several years, Microsoft has mitigated other issues where emails were quarantined or incorrectly tagged as spam or malicious. For instance, an Exchange Online bug caused anti-spam systems to mistakenly quarantine some users’ emails in March 2025, while another one caused a machine learning model to incorrectly flag emails from Gmail accounts as spam in May 2025.
More recently, in September, an anti-spam service issue blocked Exchange Online and Microsoft Teams users from opening URLs and mistakenly quarantined their emails.
The company addressed another Exchange Online issue that quarantined legitimate emails in February, after faulty heuristic detection rules designed to block credential phishing campaigns incorrectly flagged thousands of legitimate URLs as phishing links.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

