Facepalm: The list of embarrassing false positives collected by Microsoft Defender keeps growing. For a few hours, Office 365 customers were unable to open perfectly legitimate web search links because Redmond's antimalware service had decided to flag Google as a security threat.

You can pay every month for Office 365's productivity tools, but you still can't escape Microsoft Defender's habit of turning everyday links into fake security alerts. On September 2, Office 365 subscribers ran into an unusual incident: Redmond's endpoint antivirus engine began flagging Google Search results as potentially malicious URLs.

The incident was tracked as MO1465962 on the Microsoft 365 Admin dashboard and lasted roughly seven and a half hours before Microsoft resolved the underlying issue. The company explained that Google search links included in emails and Microsoft Teams messages were incorrectly identified as malicious, which in turn caused Microsoft Defender for Office 365 Safe Links to block access to those URLs across the affected apps and external browsers alike.

Safe Links is a security feature built into Microsoft Defender for Office 365, designed to protect collaboration and productivity tools from real threats. In theory, it should block phishing, malware, and other genuine dangers, which most likely does not include a routine Google Search result.

According to Microsoft's update to the MO1465962 alert, the misclassification was caused by "inaccurate" behavior in Defender's threat-detection process. The issue was marked resolved on September 2, 2026 at 10:17 UTC, though Microsoft warned that some users might still see effects while the fix propagates through its infrastructure.

Microsoft says its developers are now reviewing Defender's URL reputation classification process to prevent similar false positives going forward. We still don't know the full scope of MO1465962, though the company's "advisory" classification suggests a relatively contained incident.

At any rate, the fake Google Search alert adds to the growing list of false positives that have dogged Microsoft Defender for years. Redmond's endpoint security tool has a track record of dragging down system performance, misidentifying legitimate kernel-level drivers, and making otherwise fine software run worse than it should. Defender may be free for Windows users, but between the reliability hiccups and the zero-day vulnerabilities researchers keep finding in the engine itself, that price tag comes with real caveats.