Microsoft Defender Safe Links incorrectly blocks legitimate Google Search links
Microsoft is addressing incident MO1465962, in which Safe Links in Defender for Office 365 is marking legitimate URLs from Google Search as malicious.

Safe Links for Google Search links is the subject of incident MO1465962, which Microsoft is tracking in Defender for Office 365. The protection mechanism may block legitimate links from Google Search because it inaccurately classifies them as malicious.
Affected users may see a security warning when opening a link. Administrators may also see related alerts in the Microsoft Defender portal and Microsoft Sentinel. Microsoft said it is working on a fix for the incorrect classification.
What is causing Safe Links to block Google Search links
Safe Links checks URLs when they are clicked and is designed to protect against phishing and malicious links. In this case, however, there is no confirmed exploitation of a vulnerability or compromise of systems. Microsoft attributes the incident to inaccurate security classification of legitimate URLs—in other words, false-positive detections.
The practical impact may occur with links from email, Teams, or other Microsoft 365 applications that use Safe Links checking. Users may be prevented from accessing a search result even though the link itself is not malicious.
The scope is not yet public
Microsoft has not publicly stated the number of affected customers, regions, or the exact scope of the impact. It is also not confirmed which Google Search URL variants are affected or when the fix will be deployed.
At the time of verification, no public primary Microsoft service notification regarding incident MO1465962 was available. The alert details were relayed by BleepingComputer. Therefore, there is also no confirmed temporary procedure that would safely restore access to all incorrectly blocked links.
What administrators can monitor
Microsoft Learn documents that Defender for Office 365 administrators can manage URL allows and blocks in the tenant’s allow and block list. The documentation also includes a procedure for reporting URLs that were incorrectly classified as malicious. However, for incident MO1465962, Microsoft has not yet publicly confirmed a specific mitigation recommendation, including any potential exceptions or allowlisted URLs.
Security teams should monitor the notice regarding the fix and incident closure, as well as any official clarification about affected tenants, regions, and URLs. False positives in email protection can disrupt routine communication and may also cause users or administrators to pay less attention to security warnings.
Sources
- BleepingComputer – Relays the content of Microsoft’s service alert, the MO1465962 identifier, the cause in the form of incorrect classification, and the ongoing remediation.
- Microsoft Learn – Documents that administrators can manage URL allows and blocks in Microsoft Defender for Office 365.
- Microsoft Learn – Documents the procedure for reporting URLs that were incorrectly classified as malicious.
Verified and updated: 02. 09. 2026 13:15



