
Microsoft Is Fixing an Exchange Online Bug That’s Wrongly Quarantining Mailboxes
Microsoft is in the middle of resolving an Exchange Online problem that has been incorrectly placing customer mailboxes into quarantine since July 19, cutting off email delivery and calendar access for an unknown number of users.
What’s Going Wrong
The company is tracking the issue internally as EX1436407. Since it began, affected users have reported trouble both sending and receiving email, along with disruptions to their Exchange Online calendars. People trying to email a quarantined mailbox are getting bounce-back errors (Non-delivery Reports, or NDRs) instead of successful delivery.
Microsoft traced the root cause back to a recent change to its backend infrastructure. That change led to unexpectedly high memory usage tied to indexing data, which eventually caused an out-of-memory condition — and that, in turn, triggered mailboxes being flagged and quarantined by mistake.
Notably, this isn’t a brand-new failure mode. Microsoft says it’s a repeat of an earlier incident (tracked as EX1434354), and that extra remediation work is required this time to fully resolve it.
Where Things Stand
Microsoft hasn’t said which regions or how many customers are affected, but the incident has been formally classified as one with noticeable, active user impact.
Cleanup of the excess indexing data behind the bug has been progressing gradually — moving from 66% complete to 72% complete over the course of a single day — with mailboxes being released from quarantine as memory levels are confirmed stable region by region.
As of the most recent update, Microsoft has not given a firm timeline for a full fix, only confirming that further updates are coming.
This Keeps Happening to Exchange Online
This is far from the first time legitimate Exchange Online mail has been mistakenly blocked or quarantined:
- In March 2025, a separate anti-spam bug caused some users’ emails to be wrongly quarantined.
- In May 2025, a faulty machine learning model began flagging legitimate Gmail messages as spam.
- In September, an anti-spam service problem stopped Exchange Online and Microsoft Teams users from opening links and again quarantined emails incorrectly.
- In February, overly aggressive anti-phishing detection rules mistakenly flagged thousands of legitimate links as phishing attempts.
What Affected Users Should Do
If your organization is experiencing this issue:
- Check the Microsoft 365 admin center message center for updates tied to incident EX1436407.
- Warn your team that bounced emails (NDRs) during this window may not mean the recipient’s address is invalid — it could be the quarantine bug.
- Avoid making changes to mail flow rules or mailbox permissions while the incident is active, since that can complicate Microsoft’s remediation.
- Keep an eye on Microsoft’s incident updates for a confirmed resolution timeline once one is issued.
Source: BleepingComputer