Cybersecurity

Microsoft Defender mistakenly blocks legitimate Google Search links

Microsoft is investigating a defect in Defender for Office 365 Safe Links that caused some legitimate Google Search links to be classified as malicious and blocked from opening. IT administrators may receive incident-related alerts in Microsoft Defender and Microsoft Sentinel, with no impact scope or remediation timeline announced.

2026-09-02
3 min read
5 views
فريق تحرير certi.news
Microsoft Defender mistakenly blocks legitimate Google Search links

Microsoft has begun investigating an operational security defect that causes Defender for Office 365 to classify some legitimate Google Search links as malicious, preventing users from opening them and displaying a warning message stating that opening the website might not be safe.

The company logged the incident under the identifier MO1465962 and acknowledged it on September 2, 2026, at 10:30 a.m. Coordinated Universal Time. According to the service alert reviewed by BleepingComputer, the cause is an inaccurate security classification, not the detection of an actual threat in the affected search links.

How does the defect appear?

Users see the message “Opening this website might not be safe” when attempting to open the blocked links. Microsoft also explained that copying and pasting the link directly into the browser does not bypass the warning, meaning that the block occurs within the protection mechanism itself and not only through a clickable link in the message.

The company warned IT administrators that alerts and incidents related to these detections may appear in the Microsoft Defender portal and in the Microsoft Sentinel security information and event management solution.

What changes in practice for organizations?

Safe Links in Defender for Office 365 rewrites incoming links during mail flow and then checks them when they are clicked inside email messages, Microsoft Teams, and Office 365 applications, for organizations that have a Defender for Office 365 license. Therefore, the incorrect classification may disrupt users’ access to legitimate search results and generate false security alerts that IT teams must triage.

Microsoft did not identify the affected regions or the number of customers who encountered the problem. It also classified the incident as advisory, a designation it typically uses to describe service issues with limited scope or impact. The company said it was working to correct the incorrect classification, but it did not mention a specific completion time in the extracted material.

certi.news analysis

The significance of the incident does not lie in the presence of a new threat, but in the effect of false alarms on tools that are supposed to help organizations make rapid decisions about links. When a protection layer blocks a legitimate link, workflows may be disrupted, while security teams are forced to verify alerts that do not reflect a real risk. Conversely, the source does not establish that the defect led to a protection bypass or that any customer was subjected to an attack.

This incident points to a known limitation in automated classification systems: the accuracy of a security decision is measured not only by its ability to block malicious links, but also by its ability to avoid disrupting legitimate content. Microsoft has previously encountered similar issues in recent years that resulted in legitimate messages being classified as spam or phishing and potentially quarantined, but the source did not link these incidents to a single technical cause.

While the investigation continues, the open questions remain the scale of the impact, the affected regions, and when classification will return to its usual accuracy.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news