Turngate Status ← all systems

Alert and notification delivery delays

Resolved

Partial outage · affected Alerting & notifications · 2026-07-22 06:00 UTC → 2026-07-23 18:55 UTC (36.9 hours)

On 22 July a Microsoft Graph endpoint began returning its full global threat-intelligence catalogue (~4,955 articles) to our tenant, on an endpoint that had previously returned nothing. Our integration re-reads that catalogue every five minutes, and each pass re-saved every record, queuing a notification task for each one.

No customer data was lost and no request failed. The queue those tasks share is also used for background work such as detections, digests and in-app notifications, so that work ran behind while the backlog drained.

We cleared the backlog and shipped a fix that skips saving a record when nothing about it has changed, which stops the notifications being queued at all.

The records themselves were Microsoft general-reference threat-intelligence articles, identical for every tenant, rather than alerts about your environment. They carried no signal specific to your data, so we have stopped ingesting that source entirely.

Timeline

  1. Resolved · 2026-07-23 18:55 UTC · Kyle
    Backlog cleared and the fix is live. Background processing is back to normal. The source involved was returning a general reference catalogue rather than alerts specific to your environment, so we have stopped ingesting it.
  2. Monitoring · 2026-07-23 18:07 UTC · Kyle
    The fix is deploying to production and the queue backlog is being cleared.
  3. Identified · 2026-07-23 16:07 UTC · Peter
    Identified. An upstream provider began returning a large reference catalogue on an endpoint that had previously returned nothing. Each five-minute refresh re-saved every record and queued a notification task for each, which filled the shared background queue. A fix is in progress.
  4. Investigating · 2026-07-23 15:53 UTC · Peter
    Background processing is running behind. We are investigating a large backlog of queued work.