Microsoft Defender wrongly flags Google search links as malicious

Microsoft Defender for Office 365 Safe Links briefly blocked legitimate Google search URLs after an incorrect security classification. The issue has been

Microsoft Defender for Office 365 users can open Google search links normally again after the company fixed an incorrect security classification that briefly caused Safe Links to block legitimate Google URLs. The false positive affected organizations with a Defender for Office 365 license and triggered extra noise inside Microsoft Sentinel and the Defender portal while it lasted.

What Microsoft Defender flagged and why

The false positive hit Microsoft Defender for Office 365 Safe Links, the time-of-click URL protection feature that rewrites inbound email links during mail flow and checks URLs inside email messages, Teams, and Office 365 apps. According to a service alert, an inaccurate security classification caused Safe Links to treat legitimate Google search URLs as malicious and block access, displaying a warning that said “Opening this website might not be safe” when users tried to open the links. The flag applied to the URL itself rather than to the email wrapper, so copying a link and pasting it directly into a browser did not bypass the warning.

Incident timeline and current status

Microsoft first acknowledged the incident, tracked under MO1465962, at 10:30 AM UTC. The company did not disclose which regions were affected or how many customers were impacted, and classified the issue as an advisory, the category Microsoft typically uses for service problems with limited scope or impact. IT administrators also saw related alerts and incidents surface inside Microsoft Defender and Microsoft Sentinel as a side effect of the same bad classification. By the following day, Microsoft updated the advisory to confirm the issue had been successfully resolved, while noting that some users could continue to see impact for a limited time as the mitigation propagated through the service infrastructure.

How Safe Links is supposed to work

Safe Links is designed to stop phishing and other URL-based attacks. It rewrites hyperlinks in inbound mail during mail flow and performs a time-of-click check on URLs inside email, Teams, and Office 365 apps for organizations that hold a Defender for Office 365 license. A clean result means the user is forwarded to the destination, while a flagged result produces a warning page or a block. The feature depends on Microsoft’s URL classification staying current, which is why an inaccurate classification can cascade into a wave of false positives across every link that shares the affected pattern.

A pattern of Defender false positives

This is not the first time Defender has overreached. Over the last several years, Microsoft has worked through several similar false positive incidents. One Exchange Online bug caused a machine learning model to wrongly flag emails from Gmail accounts as spam. Another incident caused anti-spam systems to quarantine legitimate user mail. In February, a separate Exchange Online issue prevented users from sending or receiving email and quarantined legitimate messages as phishing. The pattern shows how a single bad signal in Microsoft’s detection stack can ripple out into blocks, quarantine, and admin alerts at the same time.

What IT teams can do when this happens again

When a Safe Links false positive fires, the fastest unblock for end users usually comes from a temporary policy adjustment. Admins can add the affected URL pattern to the Safe Links “do not rewrite” list through the Defender portal or PowerShell, which restores access for everyone in the policy scope while Microsoft works on a global correction. Reviewing Microsoft Sentinel and Defender alerts during an advisory lets teams tell which detections came from the bad classification and quickly suppress the noisy ones. For a more durable fix, organizations that rely heavily on Google search traffic in email should monitor Microsoft’s Service Health Dashboard for MO-numbered advisories, subscribe to the Defender for Office 365 release notes, and keep a documented playbook for Safe Links overrides so the response does not have to start from scratch each time.

Why this matters for security teams

False positives erode trust in the security stack faster than almost any other failure mode. When users repeatedly hit a “this site might not be safe” page on a destination they know is legitimate, two things happen. They learn to click through the warning, which trains a habit that defeats the very protection Safe Links provides, and they start routing around IT controls entirely by pasting raw URLs into browsers or moving sensitive work outside managed channels. Both outcomes make an organization less safe, even though the rule that fired looked correct on paper. Treating Defender misclassifications as high-priority incidents, rather than as routine noise, protects the value of the controls that remain.

FAQ

What happened with Microsoft Defender and Google search links?

Microsoft Defender for Office 365 Safe Links temporarily blocked legitimate Google search URLs after an inaccurate security classification. The issue was tracked as MO1465962 and has since been resolved, with a short tail of impact as the fix propagated.

Why did Microsoft Defender flag Google search URLs as malicious?

An inaccurate security classification in Safe Links caused the URLs to be treated as malicious. Safe Links performs a time-of-click check on URLs in email, Teams, and Office 365 apps, so a single bad classification can block many legitimate destinations at once.

How can admins unblock legitimate URLs in Microsoft Defender?

Admins can add the affected URL pattern to the Safe Links do-not-rewrite list in the Defender portal or via PowerShell, which restores access for users in the policy scope while Microsoft works on a permanent correction.

Related coverage

SEOScanPro

SEOScanPro, which includes the AI visibility report

SEOScanPro has the AI visibility report runs a full technical audit of a site and shows the measured result behind every check. Open the AI visibility report.


This article summarizes reporting from bleepingcomputer.com. See our editorial disclaimer for how our articles are produced.

🤖
Is your business visible to AI assistants?

Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.

Check Your Score →