Microsoft Investigating Teams Calling Issue Blocking Some Users From Making or Receiving Calls
Microsoft is investigating a Teams incident blocking some users from making or receiving calls.
Microsoft is investigating service incident TM1475580, disclosed on September 21 through its Microsoft 365 Status account. The company said some users may be unable to make or receive Microsoft Teams calls, without naming regions, customer segments, call types, a root cause, or a restoration time. The notice does not indicate that chat, meetings, or the wider Microsoft 365 suite are affected. Administrators are directed to the Microsoft 365 admin center for tenant-specific updates.
- Incident TM1475580 may block some users from making or receiving Teams calls.
- Microsoft did not disclose regions, root cause, or a restoration timeline.
- The notice does not say chat, meetings, or wider Microsoft 365 are down.
- A failed call alone is not evidence of compromise.
Full article479 words · extracted from cybersecuritynews.com · click to collapse
Microsoft is investigating a service incident that is preventing some users from placing or receiving calls through Microsoft Teams. The company disclosed the issue through its verified Microsoft 365 Status account on September 21, directing administrators to incident reference TM1475580 in the Microsoft 365 admin center.
The advisory is narrowly framed: Microsoft said only that “some users” may be unable to make or receive Teams calls. The brief public notice did not identify affected regions, customer segments, call types, root cause, or a restoration timeline. That distinction matters.
Organizations should avoid assuming that the issue affects chat, meetings, messaging, file sharing, identity services, or the wider Microsoft 365 suite unless their own telemetry shows otherwise.
For businesses, a call-path interruption can affect help desks, contact centers, incident-response bridges, executive communications, and remote staff. Security operations teams should also consider the operational effect on escalation procedures that depend on Teams voice.
A failed call is not, by itself, evidence of a cyberattack or an account compromise; it may instead be connected to the service-side incident under investigation. Still, teams should correlate user reports with Microsoft’s advisory and network, endpoint, and identity logs before ruling out local faults or malicious activity.
Microsoft 365 administrators should sign in to the admin center and review TM1475580 for tenant-specific impact statements and updates. Microsoft’s service-health information is generally presented within the affected customer tenant, making the admin center the authoritative source for an organization’s specific exposure.
We're investigating an issue in which some users may be unable to make, or receive calls within Microsoft Teams. For more information, please see TM1475580 in the admin center.
— Microsoft 365 Status (@MSFT365Status) September 21, 2026
They should document the time, location, client version, calling direction, and error messages reported by affected users. Administrators can then compare failures across the Teams desktop client, browser, mobile application, and network paths, while preserving evidence needed if a support case becomes necessary.
During the disruption, organizations should activate resilient communications plans rather than make broad configuration changes. Approved alternatives can include PSTN calling, a designated conference bridge, corporate mobile phones, or another sanctioned collaboration channel.
IT and security leaders should remind employees to use only approved tools for sensitive conversations, since sudden outages often create opportunities for phishing, fake support messages, and unsanctioned data sharing.
Microsoft’s investigation remains ongoing. Administrators should follow the incident record, communicate confirmed scope internally, and close any temporary workarounds once Microsoft confirms that normal Teams calling has been restored.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.