← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Microsoft Defender for Office 365 flags legitimate Google search links as malicious

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Defender for Office 365 flags Google search links as malicious.
  • Users see "Opening this website might not be safe" warnings.
  • Issue is due to an inaccurate security classification.
  • IT administrators receive alerts in Sentinel and Defender portal.

Microsoft Investigates False Positives

Microsoft is currently investigating an issue where its Defender for Office 365 security software is mistakenly flagging legitimate Google search links as malicious. This incident, tracked as MO1465962, was acknowledged by Microsoft at 10:30 AM UTC.

User Impact and Technical Details

Affected users encounter "Opening this website might not be safe" warnings when attempting to open these blocked hyperlinks. The problem stems from an inaccurate security classification within the Safe Links feature, which is designed to block malicious links in emails and Office 365 apps. Copying and pasting the links directly into a browser does not bypass the warning.

IT administrators are also seeing related alerts and incidents in Microsoft Sentinel and the Microsoft Defender portal due to these incorrect detections.

Safe Links Functionality

Safe Links operates by rewriting inbound email messages and performing time-of-click verification of URLs in various Microsoft platforms for organizations with a Defender for Office 365 license. Its purpose is to protect against phishing and other attacks by identifying and blocking malicious links.

Previous False Positive Incidents

Microsoft has encountered similar false positive issues in the past. Previous incidents include an Exchange Online bug that incorrectly flagged emails from Gmail as spam and another that quarantined legitimate emails. More recently, in February, an Exchange Online issue prevented email sending/receiving and flagged legitimate messages as phishing.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~30 min · 24 stories · Sep 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Microsoft is investigating an issue where Defender for Office 365's Safe Links feature incorrectly flags legitimate Google search links as malicious, preventing users from accessing them. This issue impacts users attempting to open blocked hyperlinks and causes alerts for IT administrators, stemming from an inaccurate security classification.