Outage status
Is Microsoft Entra ID down right now?
Entra ID: Operational · checked 1 min ago
Source · status.cloud.microsoftNot an official vendor page
No active incident in the public RSS feed
Last checked 1 min ago (5 Oct, 08:55 UTC)
Official status pageLast ~2 hours (24 checks)
Entra ID (Azure AD) sign-in outage status, Azure upstream, MFA vs outage triage, and workarounds.
1. Is it down right now?
Feed last built 5 Oct, 08:55 UTC. We only surface items from the last 72 hours and skip titles marked resolved.
Affected regions / cells: Sign-in can fail in one Azure region or for one sovereign cloud. A UK firm using Worldwide can still be fine while GCC is not.
2. Known bug — is a fix date published?
No known bug with a published fix date right now.
No open incident in the last successful fetch.
3. Plain-English workaround
From experience
If every SaaS app that uses Entra fails at once, stop chasing the app vendor. Check login.microsoftonline.com, then Azure status, then Conditional Access / MFA outage notes. Keep a break-glass account that does not require the same MFA provider.
4. Upstream or scheduled?
Vendors do not publish one shared dependency map. This list is the upstream tools we watch with this service.
- Azure OperationalEntra is an Azure identity service. Azure regional events can take sign-in with them.
Upcoming maintenance
No upcoming window in the vendor feed.
Most "SSO is down" tickets are MFA, lockout, or a certificate
If every app that uses Entra fails at once — including portal.azure.com — start at login.microsoftonline.com and the Azure identity RSS we watch. If only one app fails, it is that app's SAML/OIDC trust. Official public notes: Azure status and Microsoft 365 status.
What people report
- Approve sign-in / number matching never arrives. Authenticator, push delivery, or the user on a dead device. Not the directory being down.
- Your account is locked. Smart Lockout after password spray or a stale saved password. Wait or unlock; do not declare an outage.
- Need admin approval. Consent. An admin grants the app.
- AADSTS700016 / AADSTS50020. Wrong tenant or a deleted app registration. The error code is the diagnosis.
Okta vs Entra
If the user starts at Okta and never reaches a Microsoft password prompt, it is Okta. If they bounce to login.microsoftonline.com and die there, it is Entra. Keep a break-glass account that does not share the same MFA provider. Sovereign clouds (GCC, China) have their own login hosts.
Admin logs to open first
Entra sign-in logs, Authentication methods activity, and Conditional Access insights. If the log shows success and the app still fails, the app is lying. If the log shows failure with an AADSTS code, that code is the ticket title. Break-glass accounts should be excluded from the same MFA provider and stored offline.
Passwordless, Temporary Access Pass, and FIDO keys fail in ways that look like directory downtime. Test a second method. Official docs live with Azure status and the Microsoft 365 admin centre, not on a rumour graph.