Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft MFA Down – 504 Gateway Timeout Errors Disrupting MFA Access for U.S. Users

Microsoft is currently addressing a significant service degradation impacting Multi-Factor Authentication (MFA) within the Microsoft 365 suite. Users in North America have reported 504 gateway timeout errors when attempting to authenticate into…

Microsoft is currently addressing a significant service degradation impacting Multi-Factor Authentication (MFA) within the Microsoft 365 suite. Users in North America have reported 504 gateway timeout errors when attempting to authenticate into MFA-protected services.

The incident, identified under issue ID MO1237461 , began at approximately 8:22 PM IST (2:52 PM UTC) on Thu, Feb 23, 2026, and is under active investigation.

Users are encountering 504 Gateway Timeout responses when completing MFA challenges, blocking access to Microsoft 365 applications, portals, and any services relying on MFA in their authentication flow.

The issue appears to be due to an upstream server within Microsoft's authentication infrastructure failing to respond in time, resulting in a timeout error at the gateway layer.

Microsoft has confirmed the incident on its service health dashboard as a service degradation, indicating that some users might still authenticate intermittently based on request routing.

Affected users are effectively locked out of their accounts and associated productivity tools due to the inability to pass MFA verification.

Microsoft is currently addressing a significant service degradation impacting Multi-Factor Authentication (MFA) within the Microsoft 365 suite.
Amanda Parks · Thehackingpost

The issue primarily affects U.S.-based organizations and enterprise customers, with potential impacts on corporate email, Teams collaboration, SharePoint, and any third-party integrations using Microsoft Entra ID for federated authentication.

Conditional Access policies enforcing MFA compliance are also likely impacted, possibly affecting device logins, VPN authentication, and access to cloud-hosted business applications using Entra ID as their identity provider.

In a service update at 9:27 PM IST, Microsoft indicated it is reviewing Microsoft Entra logs and network telemetry signals to identify the root cause of the issue. Entra ID, formerly known as Azure Active Directory, is crucial to Microsoft's identity and access management platform, suggesting the issue may involve an authentication gateway, load balancer, or backend processing component.

Microsoft has issued two prior status updates during the incident at 8:23 PM and 8:56 PM IST, but no estimated resolution time has been provided.

For security-conscious organizations, the MFA downtime presents an operational challenge. Disabling MFA to regain access introduces identity risks, while enforcement leaves users locked out of critical systems.

Advertisement

IT administrators are advised to monitor the Microsoft 365 Service Health Dashboard under incident ID MO1237461 for real-time updates and consider temporary policy adjustments based on business continuity needs.

The company’s public status page shows all services as operational, but detailed incident information is available to tenants via the admin center.

Monitor the Service Health dashboard in the Microsoft 365 admin center for updates on MO1237461. Attempt signing in from different networks, devices, or browsers, or temporarily disable MFA prompts where policies permit (not recommended for production accounts). Contact Microsoft Support if business-critical access is blocked.

Microsoft’s official @MSFT365Status account on X has started sharing updates, and users are advised to monitor their tenant’s service health dashboard for the latest information, as detailed incident details are usually shared there first.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories