Microsoft’s SharePoint Outage: A Case of Misplaced TLS Certificate

245
Microsoft's SharePoint Outage A Case of Misplaced TLS Certificate

In a recent turn of events, Microsoft SharePoint and OneDrive for Business experienced a brief interruption. The cause? A German TLS certificate was erroneously added to the primary .com domains for the Microsoft 365 services.

The interruption occurred at approximately 3:08 PM ET, as reported by a Microsoft 365 advisory ‘SP659992’. The advisory warned that users might face difficulties accessing SharePoint Online and OneDrive for Business. “Users may have seen a certificate error when attempting to access SharePoint Online and OneDrive for Business. Users may also have been unable to access or present files within Microsoft Teams,” the SP659992 bulletin read.

Microsoft was quick to respond, fixing the issue within ten minutes. The tech giant attributed the problem to a recent certificate update that led to users receiving errors when trying to access the service. However, some users reported continued issues beyond the stated resolution time.

Digging deeper into the incident, it was revealed that the outage was triggered by a *.sharepoint.de TLS certificate for Germany being mistakenly added to the main sharepoint.com domain. This error resulted in a TLS common name mismatch error for visitors from the US and other countries to sharepoint.com and for any backend APIs or services connecting to the domains.

SharePoint users took to social media platforms like Reddit and Twitter to report the same TLS errors, which barred them from accessing the service. Despite the interruption being short-lived, it had a broad impact while it lasted.

This incident serves as a reminder of the critical role that proper digital certificate management plays in maintaining the smooth operation of online services. Even a minor mistake, such as the misplacement of a TLS certificate, can lead to significant disruptions, affecting users worldwide. As we continue to rely heavily on digital platforms, it’s crucial for tech companies like Microsoft to ensure stringent checks and balances in their certificate management processes to prevent such mishaps in the future.