Security advisory
Microsoft 365MediumActiveUpdated Sep 2, 2026

Microsoft Defender Flags Legitimate Google Search Links as Malicious

An inaccurate security classification in Safe Links is blocking Google search results tenant-wide, and Microsoft says even pasting the URL directly into a browser will not bypass the warning.

Emanuel De AlmeidaSep 2, 2026, 4:37 PM5 min read
Severity
Medium
Status
Active
Entity
Microsoft
Confirmed by
Microsoft service alert, via BleepingComputer

Microsoft Defender for Office 365 is blocking legitimate Google search links, wrongly flagging them as malicious, the company confirmed on 2026-09-02. Microsoft acknowledged the issue, tracked under incident MO1465962, at 10:30 AM UTC, saying affected users see an "Opening this website might not be safe" warning when they try to open blocked Google search URLs.

The bug sits in Safe Links, the Defender for Office 365 feature that rewrites and time-of-click-checks URLs in email, Teams, and Office apps, meaning the false positive can interrupt everyday browsing rather than a narrow phishing scenario.

Key takeaways

  • Microsoft confirmed the issue (MO1465962) at 10:30 AM UTC on 2026-09-02.
  • An inaccurate security classification is causing Safe Links to block legitimate Google search URLs.
  • Copying and pasting the blocked link directly into a browser does not bypass the warning, per Microsoft.
  • Admins may see related alerts in the Microsoft Defender portal and Microsoft Sentinel.
  • Microsoft classified the incident as an advisory, typically reserved for limited-scope service issues.

Affected

Vendors
MicrosoftGoogle
Products
Microsoft Defender for Office 365Safe LinksMicrosoft Sentinel

What is going on with Microsoft Defender and Google search links?

Microsoft Defender for Office 365 Safe Links is a feature that rewrites and re-checks URLs at the moment a user clicks them, guarding against phishing and malware links in email, Teams, and Office apps. On 2026-09-02, Microsoft confirmed at 10:30 AM UTC that this same feature is now misfiring against a source it should never flag: Google's own search results.

Microsoft tracks the problem under incident MO1465962 and says users hitting the bug see a page reading "Opening this website might not be safe" instead of their intended Google search result. According to a service alert reviewed by BleepingComputer, Microsoft attributes the block to "an inaccurate security classification" applied to legitimate Google search URLs, not to any change on Google's side.

Microsoft explicitly warned that pasting the blocked Google search URL straight into a browser still triggers the warning and does not bypass the issue.

That distinction matters for helpdesk teams triaging tickets, since the usual first-line advice, copy the link, open it manually, will not resolve user complaints while the underlying classification remains wrong.

Any Microsoft 365 organization licensed for Defender for Office 365 with Safe Links URL protection enforced can hit the block when a user clicks a Google search link inside email, Teams, or Office apps. Microsoft has not disclosed which regions or how many customers are affected, and BleepingComputer reports the company classified the incident as an advisory, a designation Microsoft typically reserves for service issues of limited scope or impact.

  • Microsoft 365 tenants with a Defender for Office 365 license enforcing Safe Links
  • IT administrators monitoring the Defender portal and Microsoft Sentinel for related alerts
  • End users clicking Google search result links from Outlook, Teams, or Office apps

What does this mean for security teams?

Beyond blocked links, Microsoft warned IT administrators that the misclassification generates noise inside their security tooling: related alerts and incidents can appear in both the Microsoft Defender portal and Microsoft Sentinel, the company's SIEM platform. Security teams triaging these alerts need to recognize them as false positives tied to MO1465962 rather than genuine detections requiring investigation, to avoid wasting analyst time chasing a known service issue.

Has Defender had similar false-positive incidents before?

This is not Microsoft's first false-positive incident affecting Defender for Office 365 or Exchange Online. BleepingComputer notes that a machine-learning model previously misflagged Gmail-originated emails as spam, and a separate anti-spam bug quarantined legitimate messages for other users. More recently, an Exchange Online issue in February prevented some users from sending or receiving mail and flagged legitimate messages as phishing, quarantining them.

Microsoft is separately working through a broader Microsoft 365 outage causing authentication issues, service delays, and connection problems, according to BleepingComputer, though that incident is distinct from the Safe Links classification bug.

What should admins watch for next?

Microsoft says it is "working to correct the misclassification to remediate impact," but has not published a fix timeline or confirmed which Safe Links policy configurations are involved. Admins should watch the Microsoft 365 admin center for updates tied to MO1465962 and treat Google search link blocks and related Sentinel or Defender portal alerts as expected noise until Microsoft posts resolution.

Tracking ID

Microsoft is tracking this issue as MO1465962 via a service alert.

Impact & actions

Safe Links misclassification blocks legitimate Google search URLs across Microsoft 365 tenants that enforce Defender for Office 365 URL protection, disrupting routine browsing rather than a narrow phishing scenario.

Security: The false positive generates noise in the form of related alerts in the Microsoft Defender portal and Microsoft Sentinel, which can distract analysts from genuine phishing detections during the incident window.

Recommended actions · Medium urgency

  1. 1Monitor Microsoft's service alert for updates on incident MO1465962
  2. 2Review Defender portal and Microsoft Sentinel alerts tied to this incident before treating them as confirmed threats
  3. 3Inform helpdesk staff so they can recognize and log user reports of blocked Google search links

Response

Vendor

Microsoft said: "We've determined that an inaccurate security classification is causing legitimate Google search URLs to be incorrectly identified as malicious, resulting in Microsoft Defender for Office 365 Safe Links blocking access to affected links. We're working to correct the misclassification to remediate impact."

Customer guidance

Microsoft advised admins that copying and pasting a blocked link directly into a browser will not bypass the warning, and that related alerts may appear in the Defender portal and Microsoft Sentinel while the incident is active.

Updates

Sep 2, 2026Microsoft acknowledges Safe Links false positive

Microsoft confirmed incident MO1465962 at 10:30 AM UTC and classified it as an advisory of limited scope.

FAQ

What is causing Microsoft Defender to block Google search links?

Microsoft says an inaccurate security classification is making Safe Links, part of Defender for Office 365, wrongly identify legitimate Google search URLs as malicious.

Can I work around the Safe Links block by pasting the link into my browser?

No. Microsoft says copying and pasting the blocked Google search link directly into a browser does not bypass the warning.

Which Microsoft product is affected?

The issue affects Safe Links within Microsoft Defender for Office 365, which rewrites and checks URLs in email, Teams, and Office apps.

Is this incident fixed yet?

As of Microsoft's 10:30 AM UTC update on 2026-09-02, the company said it is working to correct the misclassification but had not confirmed a fix.

Will admins see extra alerts because of this bug?

Yes. Microsoft warned that admins may see related alerts and incidents in the Microsoft Defender portal and in Microsoft Sentinel tied to the false detections.

Has Defender for Office 365 had similar false-positive issues before?

Yes. Microsoft has previously dealt with an Exchange Online bug that flagged Gmail messages as spam and a separate February incident that quarantined legitimate email as phishing.

The bottom line

Microsoft confirmed that a misclassification in Defender for Office 365 Safe Links is blocking legitimate Google search links under incident MO1465962.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles