Skip to content
Tech News
← Back to articles

Microsoft Defender flags legitimate Google search links as malicious

read original more articles
Why This Matters

Microsoft Defender for Office 365 is mistakenly flagging legitimate Google search links as malicious due to an inaccurate security classification. This issue can disrupt user access to search results and generate false alerts for IT administrators, highlighting the importance of precise threat detection in security software. The company is actively working to resolve the misclassification to restore normal functionality and reduce false positives.

Key Takeaways

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly flag legitimate Google search links as malicious.

The company first acknowledged the incident (tracked under MO1465962) at 10:30 AM UTC and says affected users are seeing "Opening this website might not be safe" warnings when trying to open the blocked hyperlinks.

According to a service alert seen by BleepingComputer, the issue is caused by an inaccurate security classification, and copying the links and pasting them directly into a browser will not bypass the warning.

Microsoft also warned IT administrators that they may see alerts in the Microsoft Sentinel security information and event management (SIEM) solution and the Defender portal regarding this ongoing incident.

"Microsoft Defender for Office 365 Safe Links may block the opening of Google search links (URLs), identifying them as malicious. In addition, admins may receive related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel as a result of these detections," Microsoft said.

"We've determined that an inaccurate security classification is causing legitimate Google search URLs to be incorrectly identified as malicious, resulting in Microsoft Defender for Office 365 Safe Links blocking access to affected links. We're working to correct the misclassification to remediate impact."

Safe Links blocks malicious links used in phishing and other attacks by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs in email messages, Teams, and Office 365 apps in organizations with a Defender for Office 365 license.

While Microsoft has yet to disclose which regions are impacted or how many customers are affected, it has classified it as an advisory, which is typically used to describe service issues involving limited scope or impact.

Microsoft has addressed similar false positive issues over the last several years that resulted in links and messages being incorrectly tagged as malicious or quarantined.

For instance, last year, an Exchange Online bug caused a machine learning model to mistakenly flag emails from Gmail accounts as spam, while another one caused anti-spam systems to quarantine some users' legitimate emails.

... continue reading