Skip to main content
CybersecurityVulnerability Management

Microsoft Defender mistakenly targets Google search links

Person sitting at desk, looking concerned at laptop screen with hands on keyboard.

"Microsoft Defender for Office 365 Safe Links may block the opening of Google search links (URLs), identifying them as malicious," Microsoft said, acknowledging an inaccurate security classification that is preventing users from opening legitimate search links.

Microsoft Defender for Office 365 Safe Links: what’s being blocked and how

Microsoft confirmed that its Safe Links feature — part of Defender for Office 365 — is marking legitimate Google search URLs as malicious and blocking access to those links. Safe Links operates by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs across email messages, Teams, and Office 365 apps for organizations licensed for Defender for Office 365. The feature’s time-of-click checks are the mechanism triggering the user-facing warning: affected users are seeing an “Opening this website might not be safe” message when they attempt to follow the blocked hyperlinks.

Incident tracking, classification error, and remediation status

Microsoft first acknowledged the incident under tracking number MO1465962 at 10:30 AM UTC. The company says the root cause is an inaccurate security classification that is incorrectly identifying legitimate Google search URLs as malicious. Microsoft is working to correct that misclassification “to remediate impact,” but it has not disclosed a timeline for a full fix.

The vendor also noted a concrete workaround does not exist in the usual sense: copying a blocked Google search link and pasting it directly into a browser does not bypass the Safe Links warning, according to the service alert seen by BleepingComputer.

Alerts in Microsoft Sentinel and the Defender portal

Administrators should expect follow-on telemetry from these detections. Microsoft warned IT teams they may receive related alerts and incidents in the Microsoft Defender portal and in Microsoft Sentinel, the company’s security information and event management (SIEM) solution. Those backend alerts reflect the same misclassification driving the user-facing blocks, and could generate additional operational noise for security operations centers while the issue is active.

Recent pattern of false positives and concurrent Microsoft 365 outage

Microsoft has previously addressed similar false-positive behaviors that affected customers. The company’s advisory notes multiple recent incidents: last year, an Exchange Online bug caused a machine-learning model to flag emails from Gmail accounts as spam; a separate event quarantined some legitimate messages; and in February an Exchange Online issue reportedly prevented sending or receiving emails and quarantined messages that were flagged as phishing. Microsoft is also working to address a separate, massive and widespread Microsoft 365 outage that is causing authentication issues, service delays and failures, connection problems, and other impacts.

How technologists, IT administrators, and end users are affected

  • Technologists and security teams: Expect increased alerts in Microsoft Sentinel and the Defender portal tied to the misclassification. Those alerts may require triage to distinguish this systemic false positive from genuine malicious activity, increasing analyst workload while Microsoft corrects the classification.
  • IT administrators and procurement leads: Administrators should watch service health notifications (noted under MO1465962) and prepare for user support requests from people who cannot open Google search links and receive “Opening this website might not be safe” warnings. Because copying and pasting a URL does not bypass the warning, there is no simple end-user workaround available from the alert Microsoft described.
  • End users and general public: Users will encounter blocked Google search links across email, Teams, and Office 365 apps when their organization has Safe Links enabled, and will see the Safe Links warning. The scope by region and the number of customers affected have not been disclosed.

Microsoft’s immediate task is narrow in description but broad in consequence: correct a security classification that is producing false positives in a widely used link-protection service. The company has labeled the matter as an advisory — a classification it typically applies to service issues with limited scope or impact — yet it has not specified which regions or how many customers are affected. Until Microsoft completes the misclassification fix, organizations using Defender for Office 365 should expect both user-facing link blocks and related alerts in their security consoles.

Source: BleepingComputer — Microsoft Defender flags legitimate Google search links as malicious