
Microsoft this afternoon figured out that changes to SafeLinks, which scans incoming email for malicious hyperlinks and attachments, caused the problem. Many delayed from yesterday."Īll this comes two months after users reported that Defender for Endpoint's attack surface reduction (ASR) rules suddenly were removing icons and application shortcuts from the Taskbar and Start Menu in both Windows 10 and 11.Ĭynics might even say Defender has had a bit of a false positive problem in the past. A poster on Reddit wrote that "pictures sent from employees personal GMAIL to work accounts getting flagged (they send pics of their receipts) and zoom links.

Perusing the Reddit comments, Zoom links seem to be a particular problem, but not the only one. "We've checked several of those URLs and all them seem a legit resource."


We're investigating why and what part of the service is incorrectly identifying legitimate URLs as malicious." Microsoft said it is trying to isolate the root cause by poring over service monitoring.Īn hour after the first tweet, Redmond followed up, saying that "users are still able to access the legitimate URLs despite the false positive alerts. "Additionally, admins may be unable to view alert details using the 'View alerts' link in the emails.'" "The high severity alert emails refer to 'A potentially malicious URL click was detected,'" according to the note.
