Microsoft is investigating a Defender for Office 365 issue that is causing legitimate Google search links to be identified as malicious, according to BleepingComputer, which cited a Microsoft service alert. The incident is tracked as MO1465962 and was first acknowledged at 10:30 AM UTC, BleepingComputer reports. Affected users attempting to open the blocked Google search URLs are shown an “Opening this website might not be safe” warning. According to the report, Microsoft attributed the issue to an inaccurate security classification. The service alert seen by BleepingComputer also said copying an affected link and pasting it directly into a browser does not bypass the warning, meaning the block is not limited to a single click path. The issue is tied to Microsoft Defender for Office 365 Safe Links, a feature that protects organizations by checking URLs at time of click. BleepingComputer notes that Safe Links rewrites inbound email links during mail flow and verifies URLs in email, Microsoft Teams, and Office 365 apps for organizations with a Defender for Office 365 license. Microsoft also warned administrators that the false detections may surface as alerts or incidents in the Microsoft Defender portal and in Microsoft Sentinel, its security information and event management product, according to the report. That makes the bug more than a user-facing nuisance: security teams may have to separate real malicious-link alerts from detections caused by the misclassification. The scope remains unclear. BleepingComputer reports that Microsoft had not disclosed which regions are affected or how many customers are impacted. Microsoft classified the matter as an advisory, which the report says is typically used for service issues with limited scope or impact. The incident fits a recurring operational risk in security automation: a protective control that is designed to stop phishing can itself interrupt normal workflows when classification goes wrong. BleepingComputer notes Microsoft has dealt with other false-positive incidents in recent years, including Exchange Online issues that misclassified legitimate mail as spam or phishing and, in some cases, quarantined messages. Microsoft says it is working to correct the misclassification, according to BleepingComputer. Until more detail is available, the material facts are the existence of the Defender for Office 365 Safe Links issue, Microsoft’s stated cause, and the possibility of related alerts in Defender and Sentinel. Who benefits: Users and administrators benefit once Microsoft corrects the classification issue. In the interim, teams with clear incident-triage processes are better positioned to handle related Defender and Sentinel alerts. Who's exposed: Organizations using Defender for Office 365 Safe Links may see legitimate Google search URLs blocked. Security teams that depend on Defender portal or Sentinel alerts may face extra triage work while the advisory remains active.