Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Abnormal Security

Account Takeover – Delayed Sign-In Event Processing (Microsoft M365 Customers)

Resolved Minor
May 29, 2026 - Started 14 days ago - Lasted 1 day
Official incident page

Incident Report

Summary AI Generated

Microsoft experienced degraded M365 sign-in audit log delivery due to a power event in their West US 2 datacenter, causing delays of up to 90 minutes in Abnormal Security's Account Takeover detection case creation for Microsoft M365 customers. The incident lasted 24.9 hours, affecting only M365-based detections while other Account Takeover data sources continued operating normally. Microsoft resolved the infrastructure issue and Abnormal initiated reprocessing to ensure all detections from the impacted timeframe were properly handled, with no sign-in data lost during the event.

Starting at 04:27 UTC on May 29, 2026, Microsoft is experiencing degraded delivery of M365 sign-in audit logs due to an issue on Microsoft's infrastructure. As a result, customers using Account Takeover detection with Microsoft M365 may see a delay of up to 90 minutes in the creation of detection cases based on sign-in activity. No sign-in data is being lost, and Abnormal has adjusted processing to account for the delay and ensure no detections are missed. All other Account Takeover data sources continue to operate at full capacity. Abnormal is actively monitoring the situation and will provide updates as it evolves. If you have any questions, please reach out to Abnormal support at support@abnormalsecurity.com.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 13 days ago - at 05/30/2026 04:14PM

Microsoft services have fully recovered from the degraded M365 sign-in audit log delivery, and Abnormal services have also recovered as of 09:41 UTC on May 30, 2026. Abnormal engineering has initiated a reprocess to ensure all Account Takeover detections from the impacted time window are properly processed. No sign-in data was lost during this event. If you experience any further issues, please reach out to Abnormal support at support@abnormalsecurity.com.

IDENTIFIED 14 days ago - at 05/29/2026 10:43PM

Microsoft has confirmed the root cause of the degraded M365 sign-in audit log delivery has been fixed and services are currently recovering. Microsoft estimates full recovery within approximately 7 hours. Once Microsoft services complete recovery, Abnormal expects Account Takeover detection to begin processing normally and will work through the backlog of sign-in events from this incident. No data has been lost. Abnormal will post a final resolved update once Microsoft confirms full restoration and backlog processing is complete.

IDENTIFIED 14 days ago - at 05/29/2026 10:23PM

Microsoft has confirmed that the degraded delivery of M365 sign-in audit logs was caused by a power event in their West US 2 datacenter, which began at 04:27 UTC on May 29, 2026. Microsoft has reported that their service is on a recovery path and is currently processing the accumulated backlog, including sign-in stream data. As a result, customers using Account Takeover detection with Microsoft M365 may continue to experience delays in the creation of detection cases based on sign-in activity until the backlog is fully consumed. No sign-in data has been lost, and Abnormal has adjusted processing to account for the delay and ensure no detections are missed. All other Account Takeover data sources continue to operate at full capacity. Abnormal will continue to monitor and provide a further update once Microsoft confirms full recovery. If you have any questions, please reach out to Abnormal support at support@abnormalsecurity.com.

INVESTIGATING 14 days ago - at 05/29/2026 03:31PM

We are continuing to investigate this issue.

INVESTIGATING 14 days ago - at 05/29/2026 03:25PM

Starting at 04:27 UTC on May 29, 2026, Microsoft is experiencing degraded delivery of M365 sign-in audit logs due to an issue on Microsoft's infrastructure. As a result, customers using Account Takeover detection with Microsoft M365 may see a delay of up to 90 minutes in the creation of detection cases based on sign-in activity. No sign-in data is being lost, and Abnormal has adjusted processing to account for the delay and ensure no detections are missed. All other Account Takeover data sources continue to operate at full capacity. Abnormal is actively monitoring the situation and will provide updates as it evolves. If you have any questions, please reach out to Abnormal support at support@abnormalsecurity.com.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook