Microsoft Exchange Online Mailboxes Quarantined Due to Out‑of‑Memory Bug, Disrupting Email Service
What Happened — An infrastructure change in Exchange Online triggered excessive memory consumption, causing an out‑of‑memory condition that mistakenly quarantined customer mailboxes. The issue, tracked as EX1436407, began on July 19 2026 and has prevented users from sending, receiving, or accessing email and calendar data.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous monitoring of Availability and Change Management controls (SOC 2 CC6.1, CC7.1) to detect and remediate misconfigurations before they affect service.
- Highlights the importance of maintaining defensible audit evidence (e.g., change logs, performance metrics) that prove controls are operating effectively during incidents.
- Aligns with Verisq’s Control Mapping capability, which automates evidence collection for change‑management and availability controls, helping you demonstrate SOC 2 readiness even when cloud providers experience outages.
Who Is Affected — SaaS and cloud‑email providers, enterprises that rely on Microsoft 365 for core communications, and any organization subject to SOC 2 availability requirements.
Recommended Actions
- Map the incident to SOC 2 Availability (CC6.1) and Change Management (CC7.1) controls; capture Microsoft’s incident updates as evidence of control monitoring.
- Verify that your own change‑control processes include validation of provider‑level infrastructure changes and that you retain logs for audit review.
- Incorporate automated evidence collection for provider‑status feeds into your continuous‑compliance dashboard.
Source: BleepingComputer
Technical Notes — The root cause was an unexpected indexing data load that exhausted memory, leading to automatic mailbox quarantine. No vulnerability (CVE) was disclosed; the event is classified as a service‑disruption misconfiguration. Source: same as above