Microsoft Defender Flags Legitimate Google Search Links as Malicious
Microsoft's Defender for Office 365 security software has been flagging legitimate Google search links as malicious, causing users to see 'Opening this website might not be safe' warnings when trying to open blocked hyperlinks. The issue is attributed to an inaccurate security classification, and copying the links directly into a browser will not bypass the warning.
Microsoft acknowledged the incident on April 1 at 10:30 AM UTC and has warned IT administrators that they may see alerts in the Microsoft Sentinel security information and event management (SIEM) solution and the Defender portal regarding this ongoing issue. The company is working to correct the misclassification to remediate the impact.
Safe Links, a feature of Defender for Office 365, blocks malicious links used in phishing and other attacks by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs in email messages, Teams, and Office 365 apps. While Microsoft has not disclosed which regions are impacted or how many customers are affected, it has classified the issue as an advisory.
This is not the first time Microsoft has faced issues with false positives. In recent years, the company has addressed similar incidents where links and messages were incorrectly tagged as malicious or quarantined due to machine learning model errors in Exchange Online.