An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Hello anju sukumaran,
Based on the symptoms, there is not enough evidence to confirm that this was a Microsoft-side outage.
The certificate warning, absence of Microsoft sign-in logs, and recovery after allowing the affected Microsoft URL to suggest that the connection may have been blocked or intercepted before it reached Microsoft 365.
I recommend checking the following:
- In the Microsoft 365 admin center, review Health > Service health, including Issues in your environment that require action.
- Open Network Connectivity and check for failed Microsoft 365 domains or TLS interception insights.
- Confirm that your firewall, proxy, DNS filter, or security product is not performing SSL/TLS inspection on the affected Microsoft 365 endpoints.
- Compare the certificate shown on an affected device with one from a working device. If the certificate issuer is your security product or organization rather than Microsoft, this indicates network interception.
- Run the Microsoft 365 network connectivity test from an affected network and retain the results for comparison.
Please also clarify which exact Microsoft URL was blocked, which Defender product or policy blocked it, and whether all affected users were connected through the same network, proxy, or security policy. Those details may help identify the common cause.
I hope this helps narrow down the source of the issue.
Feel free reply back to this post and update me on this issue, I'll be happy to help.