Defender for Office 365 Safe Links spent part of the day treating perfectly ordinary Google search URLs as a threat, prompting Microsoft to open an investigation under incident ID MO1465962 after first acknowledging the problem at 10:30 AM UTC.
Affected users were met with an ‘Opening this website might not be safe’ warning whenever they tried to follow a blocked link. Worse, the usual workaround of copying a link and pasting it directly into a browser did nothing to sidestep the warning, the classification applied regardless of how the URL was accessed.
What Defender for Office 365 Safe Links actually does
Safe Links is the feature within Defender for Office 365 that rewrites inbound email messages during mail flow and performs time-of-click verification of URLs in email, Microsoft Teams, and Office 365 apps. The idea is to intercept malicious links used in phishing and other attacks before a user can click through. When it works correctly, it is a reasonable line of defence. When it misfires on Google search results, it becomes a noisy, frustrating blocker for anyone doing something as routine as following a link from their inbox.
Microsoft confirmed the root cause in a service alert seen by BleepingComputer: an inaccurate security classification was causing legitimate Google search URLs to be incorrectly identified as malicious. ‘We’re working to correct the misclassification to remediate impact,’ the company said in its alert.
IT admins caught in the crossfire
The incident did not stay confined to end-user warning popups. Microsoft warned IT administrators that they could also see related alerts and incidents surfacing in Microsoft Sentinel and the Defender portal, meaning security teams may have spent time triaging what turned out to be phantom detections. Microsoft classified the incident as an advisory, a designation it typically reserves for issues with limited scope or impact, though it had not disclosed which regions were affected or how many customers were caught by the false positives.
According to TechSpot, the issue was marked resolved on 2 September 2026 at 10:17 UTC. Microsoft’s developers are also now reviewing Defender’s URL reputation classification process with the aim of preventing similar false positives from occurring again.
A pattern Microsoft knows well
This is not the first time Microsoft’s security tooling has turned on benign content. The company has dealt with a string of comparable false positive incidents in recent years. An Exchange Online bug caused a machine learning model to mistakenly flag emails from Gmail accounts as spam. A separate issue saw anti-spam systems quarantine some users’ legitimate emails entirely. Then, in February, an Exchange Online problem prevented users from sending or receiving emails and flagged legitimate messages as phishing, quarantining them.
Each incident follows a familiar shape: a classification model or ruleset misfires, legitimate traffic gets caught, administrators receive a flood of alerts that turn out to be noise, and Microsoft works to roll back or correct whatever triggered the misclassification. The Safe Links mechanism, because it sits directly in the path of every clicked URL in email and Office apps, is particularly exposed when that kind of error occurs, there is no graceful degradation, just a hard block.
The broader context makes the timing awkward. Microsoft was also working to address a separate, widespread Microsoft 365 outage involving authentication issues, service delays and failures, and connection problems at the same time, leaving IT teams with more than one fire to track simultaneously.
With the resolution confirmed and a review of the URL reputation classification process now under way, the immediate disruption is over. Whether the classification review will translate into fewer of these incidents is the question administrators will be watching as the next set of Defender updates rolls out.

