What the Microsoft 365 Outage Should Teach Every Small Business
Posted by: Joe Towner
On 31st August 2026, Microsoft 365 went down. Not one service, but several at once: Exchange Online, Teams, SharePoint, OneDrive for Business, Copilot, and Defender XDR all started failing within the same window. For thousands of businesses worldwide, email stopped arriving, Teams calls dropped, and files in SharePoint and OneDrive wouldn't load. The disruption ran into a second day before Microsoft reported recovery.
The cause, once the dust settled, was almost mundane: an expired authentication certificate inside Microsoft's own infrastructure. A single internal certificate, the kind of thing that quietly underpins how services check they're talking to who they think they're talking to, lapsed, and a chunk of the world's most widely used business software stack went down with it.
It's Microsoft, so it's not really about Microsoft
It's tempting to read this as “even the biggest providers have bad days” and leave it there. That's true, but it's not the useful takeaway. The useful takeaway is what an expired certificate can do, at any scale, when nobody's watching the expiry date.
Certificates aren't unique to Microsoft's back end. Every business with a website has them: SSL/TLS certificates that secure the connection to your site, and the authentication records (SPF, DKIM, DMARC) that let mail servers trust your email. We've written before about how deliverability quietly breaks when those records fall out of alignment. The same principle applies here: these things don't fail loudly until the day they do, and by then it's not a maintenance task, it's an incident.
The difference between Microsoft's outage and a typical small business incident is scale, not kind. Microsoft has entire teams dedicated to infrastructure reliability and it still happened to them. A business without anyone actively monitoring certificate expiry, DNS health, or server configuration is arguably more exposed, not less: there's no second team behind the first one to catch it.
The other lesson: what happens when your one platform goes down
If your business runs its email, files, and internal comms entirely through Microsoft 365, an outage like this doesn't just slow you down. It stops you working. No incoming email, no shared files, no Teams. For a lot of businesses, that's most of the working day gone, with no say in when it comes back.
That's not an argument for abandoning Microsoft 365. It's a genuinely solid platform, and this kind of outage is rare. It's an argument for having a fallback that doesn't depend on the same provider. A few things worth having in place before you need them:
A way to reach colleagues and clients that doesn't run through the same platform: a phone tree, a WhatsApp group, anything that isn't also Teams. Local or synced copies of the files you'd actually need to keep working for a day, rather than everything living solely in OneDrive or SharePoint. And if password resets or critical alerts route through a single mailbox, know what your Plan B is if that mailbox is unreachable for a few hours.
None of this needs to be elaborate. It just needs to exist before the day you need it, rather than being worked out in a panic while Teams is down.
How J&L Digital can help
This is the kind of thing that's easy to overlook until it costs you a day's productivity. As part of how we manage hosting and infrastructure for clients, we keep an eye on certificate expiry, DNS and email authentication records, and server configuration, so these failures get caught in routine maintenance rather than discovered mid-outage. If you're not sure what your own exposure looks like, or want a second pair of eyes on your setup, we're happy to take a look.
J&L Digital, based in Redhill, Surrey, specialises in comprehensive technology solutions including website design, software development, IT services, and digital marketing. Contact us to talk through how we can help keep your systems resilient.