Okta incident
Intermittent Access Issues with Office 365 Apps via Okta
Okta experienced a major incident on September 15, 2026 affecting Single Sign-On and Third Party, lasting 10d 9h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Sep 15, 2026, 03:15 PM UTC
At 9/15/2026 8:15 AM PT, Okta Engineering has identified an issue causing intermittent access failures when users launch Microsoft Office 365 applications, specifically Outlook, Calendar, and People, directly from their Okta Dashboard chiclets. When clicking these application chiclets, the user will receive an HTTP 401 Unauthorized error due to configured redirects. We are actively investigating the root cause. Further updates will be provided as soon as more information becomes available. Affected cells: okta-emea.com:1, okta.com:1, okta.com:2, okta.com:3, okta.com:4, okta.com:6, okta.com:7, okta.com:8, okta.com:9, okta.com:11, okta.com:12, okta.com:14, okta.com:16, okta.com:17, okta.com:18, okta.com:19, okta.com:20, okta.com:22
- investigating Sep 15, 2026, 04:22 PM UTC
Okta Engineering teams are actively working on a solution and coordinating with the service vendor to restore direct tile functionality. We'll provide an update in 30 minutes, or sooner, as additional information becomes available.
- investigating Sep 15, 2026, 04:54 PM UTC
We are continuing to work directly with our third-party service provider to troubleshoot and resolve the intermittent HTTP 401 redirect errors affecting Office 365 applications. We will provide another update as soon as new details are available.
- investigating Sep 15, 2026, 06:30 PM UTC
Active troubleshooting with our vendor remains a high-priority escalation across both engineering teams. While root cause determination is still underway, we understand the operational impact and are fully focused on driving this to resolution. Our next update will be posted as soon as new details are available.
- identified Sep 15, 2026, 11:02 PM UTC
Our third-party vendor has identified the root cause that is intermittently impacting Microsoft 365 services and is currently deploying a fix. The deployment is underway as of September 15, 2026, though complete propagation across all user accounts is expected to take approximately 48 hours to fully resolve the issue. We are actively monitoring the rollout progress and will provide further updates as new details become available. Additional root cause information will be available once the vendor has fully completed the rollout of the fix and validated full resolution.
- identified Sep 17, 2026, 10:28 PM UTC
We continue to track the issue intermittently affecting Microsoft 365 applications. Our third-party vendor has completed the fix and is actively rolling out. We anticipate an additional 24 hours to complete remediation and verify service stability. We will provide our next update by September 18, 2026, 4 PM PDT, or sooner if new details become available. Thank you for your continued patience as we work with the vendor to resolve this issue.
- monitoring Sep 18, 2026, 03:28 PM UTC
Okta teams are observing steady recovery across all environments following the deployment of a fix by our third-party vendor. As our Engineering teams continue post-remediation monitoring to ensure lasting platform stability, users who previously experienced redirection failures are now encouraged to re-test application access via their standard dashboard chiclets. Additional updates will be shared as recovery fully stabilizes across all tenant environments.
- resolved Sep 18, 2026, 11:00 PM UTC
The intermittent issue affecting Microsoft 365 applications has been addressed. Our monitoring shows a return to normal conditions. Our team is collaborating with our third-party vendor to identify the underlying root cause, and a Root Cause Analysis will be forthcoming.
- resolved Sep 26, 2026, 12:22 AM UTC
We sincerely apologize for any impact this incident has caused to you, your business, or your customers. At Okta, trust and transparency are our top priorities. Outlined below is the RCA summary for a recent incident where a third-party provider or downstream service experienced an issue that impacted the Okta service. We are committed to implementing improvements to the service to prevent similar occurrences. Detection and Impact: On September 15, 2026, at 06:33 UTC, Okta customers utilizing identity provider-initiated sign-on flows for Office 365 Outlook, Calendar, and People applications began encountering intermittent HTTP 401 Unauthorized errors upon redirection. End users successfully completed authentication through Okta, but were unable to reach the target applications when selecting application tiles. Root Cause Summary: An architectural update to Microsoft’s infrastructure inadvertently affected incoming requests via legacy application redirection paths, resulting in HTTP 401 Unauthorized errors. While Okta completed session authentications and policy evaluations as expected, session handoffs failed at Microsoft’s endpoints due to changes in legacy assembly handling. Okta services remained fully operational throughout the event. Remediation Steps: Okta Engineering worked directly with Microsoft to identify and escalate the issue for resolution. Okta then monitored service telemetry until Microsoft completed the deployment of a software fix across its production environments, confirming full mitigation on September 18, 2026, at 17:30 UTC. Preventive Actions: Okta is implementing dynamic runtime URL configuration capabilities to allow application tile target URLs to be updated without requiring standard release cycles. Timing: Incident start: September 15, 2026, at 06:33 UTC Incident resolved: September 18, 2026, at 17:30 UTC Duration (# of minutes): 3 days, 10 hours, and 57 minutes.