Safe Link is crazy: Defender classifies harmless Google links as malware

Microsoft Defender suddenly hunts down harmless Google links instead of viruses and blocks users from their own searches. A classification error in “Safe Links” causes completely normal Google URLs to be marked as malware. Microsoft is working on a solution.
Switching to the target page is denied
An error in Microsoft Defender causes completely harmless Google search links to be incorrectly classified as dangerous and blocked. When clicking on such links in emails or Microsoft Teams, affected users will see the warning “This website may not be safe to open” and will not be able to reach the target page.
The issue affects the “Safe Links” feature within Microsoft Defender for Office 365. Safe Links checks URLs in incoming emails, Teams messages and supported Office apps for malicious content and can block links if in doubt.
However, due to incorrect security classification, legitimate Google search URLs are currently being marked as “malicious”. This not only leads to blocked links for end users, but also to a flood of alerts and incidents in the Microsoft Defender and Microsoft Sentinel admin portals. Microsoft documented the incident in the Microsoft 365 Admin Message Center. The company says it has identified the cause and is working to correct the misclassification; however, an exact timeline for the full fix was not given.
Defender warning page
For end users in affected organizations, this means in everyday life that they cannot open Google search links from emails or Teams; the typical Defender warning page appears. According to reports, bypassing it by copying and pasting the URL directly into the browser does not help because the blocking takes effect at the link level.
IT administrators are seeing increased reports in the Defender portal and Sentinel, even though there is no real threat from Google. Microsoft classifies the reach as limited, but does not provide any specific numbers or regions.
Safe link function is crazy
Safe Links is a central building block of email and collaboration security in Microsoft 365. The feature is intended to ward off phishing, malware and business email compromise by re-checking URLs at click time and blocking them if necessary. It is precisely this mechanism that is now causing confusion: a security feature, of all things, blocks a large number of harmless everyday links – and at the same time generates alarm noise in the security consoles.
The incident joins a series of Defender problems in recent weeks, including false alarms after a Windows 11 preview update and temporary disruptions in virus scans during a zero-day repair. Microsoft emphasizes that there is no real danger from the Google links – it is an incorrect classification on Microsoft’s side. As soon as the correction has started, the blockages and the associated false reports should disappear.
Digital marketing enthusiast and industry professional in Digital technologies, Technology News, Mobile phones, software, gadgets with vast experience in the tech industry, I have a keen interest in technology, News breaking.