Cybersecurity · Resilience

Email Continuity: What Happens When Microsoft 365 Goes Down

Email is the one system a modern organisation genuinely cannot run without for long. Yet most business continuity plans quietly assume it will always be there. When Microsoft 365 has an outage, and it does, the question is simply whether your people can still send and receive. That is what email continuity is for, and it is a different job from backup and from archiving.

Ask most IT teams what happens if email stops for half a day, and you get an uncomfortable pause. Firewalls have failover. Storage has replication. The data centre has generators. Email, the one channel that every department, customer and supplier relies on hour by hour, is often left with no plan at all beyond a quiet faith that the cloud will hold. It usually does. The problem is the days when it does not.

In short

Moving to Microsoft 365 did not remove the risk of an email outage, it moved it somewhere you no longer control. When the platform has a bad day, your business stops sending and receiving, and there is nothing your own team can do to bring it back. Email continuity is an independent service that keeps mail flowing during that outage and syncs everything back when the platform returns. It is not a backup and it is not an archive. It is availability.

The outage nobody plans for

The move to cloud email quietly changed the shape of the risk. On premises, an outage was yours to fix, and yours to prevent. In the cloud, the resilience is genuinely excellent most of the time, far better than most organisations ran themselves, but on the rare occasion it fails, you are a spectator. Microsoft 365 has had real, widespread outages, some lasting hours, affecting mail flow, sign in and the admin tools all at once. During one of those, your helpdesk cannot escalate, your team cannot log a ticket that helps, and everyone simply waits.

That is the uncomfortable truth of a single platform. When it is up, it is superb. When it is down, your exposure is total and your control is zero.

Why "it is in the cloud, so it is fine" does not hold

The common assumption is that the platform's own uptime commitment covers this. It does not, and the distinction matters. Microsoft's service level agreement is a financial promise, not an availability one. If uptime drops below the committed figure, you may be entitled to a service credit against your bill. A credit does not send the invoice that had to go out this afternoon, and it does not answer the customer waiting on a reply.

This is the shared responsibility model that applies across cloud services. The provider runs the platform to a high standard. The availability of your business, the continuity of your operation when the platform stumbles, remains your responsibility to plan for. Assuming otherwise is the gap that turns a provider outage into your crisis.

What email downtime actually costs

The cost of an email outage is easy to underrate because it is spread thin across everyone at once. Sales cannot progress deals. Finance cannot chase or confirm payments. Support goes dark to customers who expected a reply. Operations lose the thread of decisions that live in the inbox. For a regulated or transaction heavy business, even a few hours can carry a real financial and reputational price, and unlike a single failed server, it lands on the whole organisation simultaneously. Email is not one system among many. For most of the working day it is the nervous system, and when it stops, coordinated work stops with it.

What email continuity gives you

Email continuity is an independent service that sits alongside your mail platform and takes over the moment the platform is unavailable. The point is simple. Your people keep working through the outage, on the tools they already use, and nothing is lost.

  • Send and receive during the outage. Mail continues to flow through the independent service, so inbound messages still arrive and your team can still reply, even while the primary platform is completely down.
  • The tools people already use. Access continues through Outlook for Windows, through a native app on Mac, and through a mobile app, so there is no scramble to learn something new in the middle of an incident.
  • Nothing falls through the gap. When the platform comes back, everything sent and received during the outage automatically reconnects and synchronises into the mailbox, so there is no manual reconciliation and no lost messages.
  • Cover for the length that matters. Continuity is designed to carry a full failover for durations from around twenty four hours through several days, which covers the realistic length of a serious platform outage.

How it works in an incident

The mechanics are deliberately undramatic, which is the whole idea. When an outage hits, an administrator triggers a continuity event, and mail routing shifts to the independent platform. Users carry on sending and receiving through their normal client or the mobile app, with access to recent mail and calendar. When the primary platform is healthy again, the service reconnects and synchronises every message from the outage window back into the mailbox, then hands normal service back. A good continuity setup is one your people barely notice, because the alternative is everyone noticing very much.

Three different jobs, often confused

Continuity, backup and archive are not the same thing, and one does not cover another. Continuity keeps mail flowing during an outage, it is about availability now. Backup is about recovering data you lost or that was corrupted. An archive is a long term, tamper evident record you can search for compliance and legal need, covered in our guide on email archiving, retention and eDiscovery. A resilient email estate usually needs all three, because each answers a question the others do not.

Where Mimecast Mailbox Continuity fits

We are a strategic Mimecast partner, and where uptime is genuinely business critical we recommend Mimecast Mailbox Continuity for specific reasons rather than as a default. It is independent of the mail platform, so an outage on Microsoft 365 does not take the continuity service down with it. It lets people keep working through Outlook for Windows, a native Mac app and a mobile app, so there is no disruption to how they work. It reconnects and synchronises automatically once the platform recovers, so nothing from the outage is lost. And it is backed by a full service availability commitment, delivered from geographically dispersed data centres with built in redundancy. Where a few hours of lost email would genuinely hurt, that independence is the point. Where it would be a mild inconvenience, it may not be worth it, and we will say so.

Check where you stand first

Not sure whether your email estate could survive a platform outage, or where the other gaps sit? Our free, interactive Email Security Assessment covers resilience and continuity alongside the other dimensions of email and collaboration defence, and returns an instant, personalised view of where you are exposed. It is the quickest place to begin.

Could your business keep working if email went down for a day?

C4C helps organisations build genuine email resilience, continuity for the outage, backup for recovery and an archive for the record, sized to what your business actually needs. Vendor neutral, with no quota to fill.

Prefer email? Reach us directly at hello@c4cgroup.co.uk.

Frequently asked questions

What is email continuity?

Email continuity is an independent service that keeps your organisation sending and receiving mail during an outage of your primary platform, such as Microsoft 365. When the platform is unavailable, mail flows through the continuity service instead, and everything synchronises back to the mailbox once the platform recovers. It is about availability, keeping people working, rather than security or long term storage.

Does Microsoft 365 ever go down?

Yes. The platform is highly resilient and available the overwhelming majority of the time, but it has had real, widespread outages that affected mail flow, sign in and the admin tools together, some lasting several hours. The point of continuity is not that outages are common, it is that when one happens your own team cannot fix it, so you need an independent way to keep working.

Is the resilience built into Microsoft 365 enough?

For many organisations the platform's own resilience is enough day to day, but its service level agreement is a financial promise, not a guarantee that your mail keeps flowing. If uptime falls short you may receive a service credit, which does not send the message that had to go out or answer the waiting customer. Under the shared responsibility model, planning for your own availability during an outage remains your job.

What is the difference between email continuity, backup and archiving?

They are three different jobs. Continuity keeps mail flowing during an outage, so it is about availability right now. Backup is about recovering data that was lost or corrupted. An archive is a long term, tamper evident record you can search for compliance and legal purposes. One does not cover another, and a resilient email estate usually needs all three.

How does email continuity work during an outage?

When an outage hits, an administrator triggers a continuity event and mail routing shifts to the independent service. People keep sending and receiving through their normal client or a mobile app, with access to recent mail and calendar. When the primary platform is healthy again, the service reconnects and synchronises every message from the outage window back into the mailbox, then normal service resumes.

Does Mimecast guarantee email uptime?

Mimecast Mailbox Continuity is backed by a full service availability commitment, delivered from geographically dispersed data centres with built in redundancy, and it is independent of your mail platform so an outage there does not take continuity down too. It lets people keep working through Outlook, a Mac app and mobile during an outage, and synchronises everything back afterwards. We recommend it where uptime is business critical rather than as a default.