Microsoft Defender for Office 365 Falsely Flags Google Search Links as Malicious
IT security professionals and privacy-conscious users are facing an unexpected hiccup: **Microsoft Defender for Office 365** is mistakenly identifying legitimate **Google** search links as malicious. This issue, tracked under **MO1465962**, is causing 'Opening this website might not be safe' warnings, disrupting workflow and potentially raising undue alarms within organizations.

**Microsoft** is currently investigating an incident where its **Defender for Office 365** security software is incorrectly flagging legitimate **Google** search links as malicious. This misclassification is leading to 'Opening this website might not be safe' warnings for users attempting to access these links.
### The Root of the Problem
The issue, acknowledged by **Microsoft** at 10:30 AM UTC and tracked as **MO1465962**, stems from an inaccurate security classification. Users are finding that even copying and pasting the links directly into a browser does not bypass the warning, indicating a deeper system-level block.
### Impact on IT Administrators
IT administrators should be aware that this incident may trigger related alerts and incidents within **Microsoft Sentinel** (the security information and event management solution) and the **Defender** portal. **Microsoft** has stated: "**Microsoft Defender for Office 365 Safe Links** may block the opening of **Google** search links (URLs), identifying them as malicious. In addition, admins may receive related alerts and incidents in the **Microsoft Defender** portal and **Microsoft Sentinel** as a result of these detections."
### How Safe Links Operates
**Safe Links** is a crucial component of **Defender for Office 365**, designed to protect against phishing and other attacks. It works by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs across email messages, **Teams**, and **Office 365** applications for licensed organizations.
### Historical Context of False Positives
While **Microsoft** has classified this as an advisory, suggesting limited scope, it's not an isolated incident. The company has a history of addressing similar false positive issues. In the past, an **Exchange Online** bug mistakenly flagged emails from **Gmail** accounts as spam, and other instances saw legitimate user emails being quarantined or prevented from being sent or received due to misclassification as phishing attempts.
**Microsoft** is actively working to correct the misclassification to mitigate the impact of this ongoing issue.