Microsoft had to fix an embarrassing error in its security system: Defender for Office 365 started to report normal Google search links as dangerousshowing users the “Opening this website might not be safe” warning every time they tried to open them. The outage was traced internally with the code MO1465962.
To complicate matters, even copying the address and pasting it directly into the browser did not allow the block to be circumvented: the problem lay upstream, in the function Safe Linkswhich rewrites incoming email URLs and checks them for security upon click in Outlook, Teams, and other Office 365 apps.
A wrong classification at the root, embarrassing bug on Microsoft Defender
According to a service alert consulted by BleepingComputer, the cause must be found in one imprecise safety classification which labeled Google search URLs as malicious. Microsoft also warned IT administrators to expect anomalous reports in both the Defender portal and Microsoft Sentinelthe company’s SIEM system, due to false positives generated by the incident.
In the note, Microsoft explained that “Incorrect security classification is causing legitimate Google search URLs to be improperly identified as malicious“, resulting in a block by Safe Links. The company did not specify which geographic areas or how many customers were affected, while the incident was classified as “advisory”, a category reserved for problems of limited scope or impact.
The case adds to a series of similar episodes already faced by Microsoft in recent years. Previously, a bug in the machine learning model of Exchange Online had labeled emails from Gmail accounts as spam, while another failure led to legitimate messages being quarantined. Furthermore, last February, a similar problem on Exchange Online prevented the sending and receiving of emails, resulting in even regular communications being reported as phishing.
The episode also comes as Microsoft is grappling with a Wider outage on Microsoft 365which caused authentication issues, service delays, and connection difficulties on a larger scale.
In the past few hours, Microsoft has announced that “the problem was successfully resolved”while warning that some users may continue to experience residual effects for a limited period, waiting for the correction to fully spread to the service infrastructure.

