IT departments are facing an urgent operational incident following reports that Microsoft's KB5002907 update for Microsoft 365 is deactivating and, in some cases, entirely removing perpetual Office 2016 and Office 2019 installations. Microsoft has now paused the update's rollout in response.
The issue specifically targets the local licensing validation for perpetual, one-time-purchase Office licenses, leaving cloud-based Microsoft 365 subscription users unaffected. Administrators are reporting that after the update's installation, their perpetual Office suites become inoperable, with some systems showing the software has been completely uninstalled. This creates significant disruption for organizations relying on these traditional licensing models.
Microsoft has acknowledged the problem and halted further distribution of the problematic patch. However, the company has not yet released a root cause analysis or a timeline for a corrected update. This transparency gap forces IT teams to manage risk without complete vendor guidance, demanding immediate attention.
For IT professionals in Hong Kong, this event is a high-priority incident that reinforces the critical need for staged, ring-based patch deployment and pre-release testing. The following four-step response is recommended to mitigate operational risk immediately.
Immediate Response Checklist
- Block the Update: Suspend all deployments of KB5002907 immediately. Use group policy or your organization's update management tools to block this specific update number across all systems.
- Audit and Verify: Conduct an immediate audit to identify any systems where the update may have already installed. Verify the activation status of all Office 2016 and 2019 installations and check for any signs of removal.
- Plan Remediation: Prepare a remediation plan for affected systems. Reactivation will typically involve using the original licensing channel (e.g., a Volume Licensing Server) or re-entering a product key. Note that recovery for end-of-life Office 2016 installations may prove more complex.
- Monitor Official Channels: Closely watch the official Microsoft Support bulletin for KB5002907 and the Microsoft 365 admin center for updates on a root cause, a permanent fix, and further guidance.
This incident serves as a concrete case study on why controlled, pre-tested patch rollouts are non-negotiable for maintaining operational stability.
IT部門正因應Microsoft 365的KB5002907更新導致永久Office 2016及Office 2019安裝被停用、甚至在某些情況下被完全移除的報告,面臨一場緊急營運事故。Microsoft現已暫停該更新的推出以作回應。
該問題專門針對一次性購買的永久Office授權的本地授權驗證,雲端Microsoft 365訂閱用戶則不受影響。管理員報告指,更新安裝後,其永久Office套件變得無法操作,部分系統更顯示軟件已被完全卸載。這對依賴這些傳統授權模式的機構造成重大干擾。
Microsoft已承認此問題並停止派發有問題的修補程式。然而,該公司尚未發布根本原因分析或修正更新的時間表。這種資訊落差迫使IT團隊在沒有完整供應商指引的情況下管理風險,需要立即關注。
對香港IT專業人員而言,這事件是一宗高優先級事故,再次突顯分階段、分環部署修補程式及進行預發布測試的關鍵必要性。建議立即執行以下四步驟回應以降低營運風險。
即時回應清單
- 阻止更新: 立即暫停所有KB5002907的部署。使用群組原則或組織的更新管理工具,在所有系統上封鎖此特定更新編號。
- 審計與驗證: 立即進行審計,以識別任何可能已安裝該更新的系統。驗證所有Office 2016及2019安裝的啟用狀態,並檢查是否有任何被移除的跡象。
- 規劃補救: 為受影響系統制定補救計劃。重新啟用通常涉及使用原始授權渠道(例如大量授權伺服器)或重新輸入產品金鑰。請注意,已結束支援的Office 2016安裝的恢復可能更為複雜。
- 監察官方渠道: 密切關注Microsoft Support關於KB5002907的官方公告及Microsoft 365管理中心,以獲取根本原因、永久修正方案及進一步指引的更新。
此事件具體例證了為何受控、經預測試的修補程式推出,對維持營運穩定性不可或缺。
