The news
An Azure outage disrupted network connectivity for a subset of Microsoft (MSFT) customers using gateway services from 20:30 UTC on September 30, 2026, to 02:15 UTC on October 1. Microsoft said a recent change to a gateway management service set it off during routine maintenance.
Microsoft's Azure status history names the affected services as Azure ExpressRoute Gateway, Azure VPN Gateway, Azure VMware Solution, Azure Firewall, and Azure Application Gateway with Web Application Firewall. ExpressRoute is a private connection between a company's own data centers and Azure, and VPN Gateway links offices to Azure over encrypted internet tunnels. Together they are the plumbing of hybrid cloud, where companies run systems both on their own premises and in a public cloud.
In its preliminary account, Microsoft said the gateway management change triggered higher-than-expected load as unrelated operating system servicing maintenance moved gradually through multiple regions. The management service would normally scale up on its own, the company said, but rising demand on services it depends on stopped those regional services from scaling as expected.
According to Microsoft's timeline, impact began at 20:30 UTC (4:30 p.m. US Eastern time) on September 30. Engineers began investigating at 21:29 UTC, found by 22:27 UTC that several regions were involved and paused the OS servicing at 23:05 UTC. Microsoft said it reverted the gateway manager change, which cut the load and let services recover, and applied configuration changes to the remaining impacted regions, including France Central, North Europe, Southeast Asia, UK South and UK West. It declared the issue mitigated at 02:15 UTC on October 1 (10:15 p.m. Eastern on September 30).
Reporting while the incident was under way, The Register said 18 Azure regions were affected at the time of writing, including West US, West US 3 and Mexico Central. The outlet quoted Microsoft status updates saying some VPN gateways had reduced redundancy rather than a complete loss of connectivity, and that some network management components had not recovered automatically, causing management operations to fail in a subset of regions. The Register called the event a "self-inflicted wound" and noted that Microsoft had not yet identified a root cause at that point.
Microsoft said it will complete an internal retrospective, generally within 14 days, and then publish a post incident review (PIR) to all impacted customers. It advised customers to configure Azure Service Health alerts to be notified.
The numbers
- Impact window (Microsoft)
- 20:30 UTC Sept. 30 to 02:15 UTC Oct. 1, 2026
- Azure regions affected at time of writing (The Register)
- 18
- Services named by Microsoft
- 5 (ExpressRoute Gateway, VPN Gateway, Azure VMware Solution, Azure Firewall, Application Gateway/WAF)
- Internal retrospective before final PIR (Microsoft)
- Generally within 14 days
Why CEOs should care
For CIOs and infrastructure leaders, this outage hit the connections that tie offices and data centers to Azure, not just the workloads inside it. Check whether your ExpressRoute circuits and VPN gateways sit in a single region, whether you have a tested backup path (for example a VPN fallback for ExpressRoute) and whether failover to another region actually works. Ask your Microsoft account team which of your resources were in affected regions and request the PIR when it is published.
For CISOs, Azure Firewall and Web Application Firewall were on the list, and Microsoft status updates cited by The Register said management operations failed in some regions. That means teams may not have been able to change security settings during the incident. Confirm whether your security gateways fail open or closed, and make sure your incident runbooks include a way to manage network rules if the cloud console cannot.
For CFOs and procurement, review the service-level agreements for each affected service and the deadline for filing credit claims. Boards should note the root cause: two routine provider activities, a software change and OS maintenance, combined into a multi-region disruption. Ask vendors how they stagger changes so that maintenance and new code do not roll through regions at the same time.
The bigger picture
By Microsoft's account, the trigger was its own change, not an attack or a hardware failure. Microsoft's status history also lists an incident on September 29 with intermittent request failures and higher latency across Azure OpenAI, Azure AI Foundry and Cognitive Services, and a July 23 post incident review for network connectivity problems in West US.
As more companies route traffic to Azure through private links and managed gateways, the management layer behind those gateways becomes a shared point of failure. Resilience plans that assume a single region's networking will stay up need a second look.
What’s next
Watch for Microsoft's final post incident review, due after an internal retrospective that Microsoft says is generally completed within 14 days. It should settle the gap between the 18 regions The Register reported during the incident and the five regions Microsoft named in its mitigation notes, and explain what Microsoft will change in how it rolls out gateway updates and maintenance.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








