Microsoft Defender for Office 365 is mistakenly blocking legitimate Google search links, warning users that opening them may be unsafe.
Microsoft said the incident, recorded as MO1465962, is being investigated after an inaccurate security classification caused genuine Google URLs to be treated as malicious by its Safe Links service.
Users attempting to follow affected links may see the message: “Opening this website might not be safe”. Copying the link and pasting it directly into a browser does not avoid the warning, according to Microsoft’s service alert.
The company acknowledged the problem at 10.30am UTC and has not said how many customers or which regions are affected. It has categorised the incident as an advisory, a designation generally used for issues with a limited scope or impact.
Microsoft also warned administrators that the false detections could generate related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel, its security information and event management platform.
“Microsoft Defender for Office 365 Safe Links may block the opening of Google search links (URLs), identifying them as malicious,” the company said. “In addition, admins may receive related alerts and incidents in the Microsoft Defender portal and Microsoft Sentinel as a result of these detections.”
Safe Links is designed to protect organisations from phishing and other online attacks. It rewrites links in incoming emails and checks their safety when users click them in email, Microsoft Teams and Office 365 applications.
Microsoft said it was working to correct the misclassification and restore access to the affected Google search links.
The company has dealt with other false-positive problems in its email security systems in recent years, including incidents in which legitimate messages were identified as spam, quarantined or labelled as phishing.
