Microsoft Defender for Office 365 is blocking legitimate Google search links and labeling them as unsafe, preventing users in affected organizations from opening them. Microsoft has since resolved the underlying misclassification, though some users may continue to see warnings while the mitigation propagates.
What happened with Defender for Office 365?
Microsoft confirmed on September 2, 2026 that its Defender for Office 365 Safe Links feature was incorrectly flagging Google search URLs as malicious. Users trying to open these links received an “Opening this website might not be safe” warning. The incident was tracked internally as MO1465962 and first acknowledged at 10:30 AM UTC.
Why are Google links being blocked?
Microsoft identified the root cause as an inaccurate security classification. The Safe Links feature, which is designed to block phishing and other malicious URLs by rewriting inbound email links and performing time-of-click verification across email, Teams, and Office 365 apps, applied the wrong verdict to legitimate Google search links. As a result, those links were blocked automatically.
Microsoft also noted that copying the affected links and pasting them directly into a browser does not bypass the warning. IT administrators in affected organizations could see related alerts and incidents generated in the Microsoft Defender portal and in Microsoft Sentinel, the company’s security information and event management (SIEM) platform.
How is Microsoft fixing the false positives?
According to Microsoft’s updated advisory, “the issue has been successfully resolved.” However, the company cautioned that “some users may continue to experience impact for a limited time while the mitigation propagates through the service infrastructure.” This means cached Safe Links verdicts may take time to refresh across the service.
How widespread is the impact?
Microsoft has not disclosed which regions are affected or how many customers are experiencing the false positives. The company classified the incident as an advisory, a category Microsoft typically uses for service issues involving limited scope or impact.
How does Safe Links normally work?
Safe Links is part of Microsoft Defender for Office 365 and is available to organizations with a Defender for Office 365 license. It works in two stages: it rewrites inbound URLs in email messages during mail flow so they route through Microsoft’s verification service, and it performs a time-of-click check on those links when a user attempts to open them in email, Teams, or Office 365 apps. Links deemed malicious are blocked, while safe links forward users to the original destination.
Has Microsoft had false positive issues like this before?
Microsoft has dealt with several similar false positive incidents in recent years. In 2025, an Exchange Online bug caused a machine learning model to flag emails from Gmail accounts as spam. Another Exchange Online issue around the same period caused anti-spam systems to quarantine legitimate messages. In February 2026, a separate Exchange Online problem prevented users from sending or receiving email and quarantined legitimate messages as phishing.
What should organizations do in the meantime?
Microsoft’s advisory indicates that affected organizations do not need to take action on their end, as the misclassification has been corrected and the fix is rolling out through the service. Admins who continue to see Safe Links warnings on Google search URLs can wait for the mitigation to fully propagate, or open the affected links from a device or browser session that is outside the Safe Links policy scope.
FAQ
Why is Microsoft Defender blocking Google search links?
Microsoft confirmed the blocks were caused by an inaccurate security classification in Defender for Office 365 Safe Links. The feature was wrongly flagging legitimate Google search URLs as malicious. Microsoft has since corrected the misclassification.
Does Microsoft Defender still flag Google links as malicious?
Microsoft stated that the issue has been successfully resolved, but added that some users may continue to see warnings for a limited time while the fix propagates through the service infrastructure.
What is Microsoft Defender for Office 365 Safe Links?
Safe Links is a feature in Microsoft Defender for Office 365 that rewrites inbound email links and checks them at the time of click in email, Teams, and Office 365 apps. Links identified as malicious are blocked to protect users from phishing and other attacks.
This article summarizes reporting from bleepingcomputer.com.
