Microsoft Defender for Office 365 Incorrectly Blocks Legitimate Google Search Links
Microsoft is investigating a false-positive issue in Defender for Office 365 that is causing legitimate Google search links to be incorrectly identified as malicious and blocked by Safe Links.
The company acknowledged the incident at 10:30 a.m. UTC under service alert MO1465962. Users who attempt to open an affected hyperlink may see a warning stating that “this website may not be safe to open.”
According to Microsoft’s service alert, the problem is being caused by an inaccurate security classification. Copying and pasting the affected URL directly into a browser will not bypass the Microsoft Defender warning.
IT administrators may also see related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel security information and event management (SIEM) platform while the issue remains active.
“Microsoft Defender for Office 365 Safe Links may block Google search links (URLs) from being opened and identify them as malicious. Additionally, administrators may receive related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel as a result of these detections,” Microsoft said.
“We have discovered that an inaccurate security classification incorrectly identifies legitimate Google search URLs as malicious, resulting in Microsoft Defender for Office 365 Safe Links blocking access to the affected links. We are working to fix the incorrect classification to remediate the impact.”
Safe Links is designed to protect organizations from phishing and other cyberattacks. The security feature rewrites links in incoming email during mail flow and validates URLs when users click them in email messages, Microsoft Teams, and Microsoft 365 applications.
Microsoft has not disclosed which regions are affected or how many customers are experiencing the problem. The company has classified the incident as an advisory, a designation generally used for service issues with limited scope or impact.
This is not the first time Microsoft has dealt with false positives affecting legitimate links or messages. In recent years, similar bugs have caused valid content to be incorrectly marked as malicious, flagged as spam, or placed in quarantine.
For example, a bug in Exchange Online caused machine learning systems to incorrectly classify emails from Gmail accounts as spam. Another issue caused Microsoft’s anti-spam systems to quarantine legitimate messages belonging to some users.
More recently, an Exchange Online incident in February prevented some users from sending or receiving email, incorrectly flagged legitimate messages as phishing, and moved them to quarantine.
Microsoft is also working to resolve a widespread Microsoft 365 outage that is causing authentication problems, service delays, connectivity issues, and other disruptions.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



