Microsoft Defender for Office 365 is misclassifying ordinary Google search links as malicious, showing an "Opening this website might not be safe" warning across Safe Links, Sentinel and the Defender portal since 10:30 AM UTC on September 2, 2026, and Microsoft says there is no workaround yet.
Read the full story: Microsoft Defender Flags Legitimate Google Search Links as Malicious →
Transcript
Microsoft Defender just started blocking Google. Not a hacked version of Google, the real thing. Microsoft confirmed the issue this morning under ticket MO1465962, and the cause is what they call an inaccurate security classification, a false positive baked into Defender's own detection model. The warning reads Opening this website might not be safe, and it shows up anywhere Defender's Safe Links feature checks a URL, which for most Microsoft 365 tenants means every link in Outlook, Teams, and OneDrive. Copying the raw Google link into a browser does not help either, there is no workaround right now. It gets worse for security teams. The same bad classification is generating alerts inside Microsoft Sentinel, so analysts are seeing a flood of malicious URL warnings that are not attacks at all, just noise from Microsoft's own tooling. And this is not new. Back in March twenty twenty three, Defender went through nearly the identical failure, misflagging Zoom and Google under a different ticket. The fix that time was a rollback. If you run Defender for Office 365, flag this ticket in your Service Health dashboard and treat Google-domain alerts as known noise until Microsoft ships a fix.