Microsoft Defender for Cloud: URL classification issue causing service access disruption — Urgent investigation needed

Darren Mizzi 21 Reputation points
2026-10-01T15:36:47.1366667+00:00

Problem description

I am experiencing an issue where URLs under my custom domain are being classified as malicious by Microsoft Defender's Safe Links feature, leading to access disruptions for my production service. The URLs work normally outside of Microsoft products, but within Microsoft applications, they are flagged as malicious.

Environment

The affected environment involves a production service accessed via URLs on a custom domain, with the issue related to Safe Links URL reputation classification. Specific resource types, regions, or subscription details are not provided.

What I've already tried

I have reviewed the case details and attempted to understand the cause of the false-positive URL classification. The case documentation indicates that the issue is a Safe Links false positive, and I have reviewed public Safe Links documentation on URL exceptions and submitting URLs for review. No specific troubleshooting steps or configuration changes have been documented or confirmed in the case record.

Current status

The issue persists since the initial report on October 1, 2026, with URLs being flagged as malicious, impacting customer access to the service. I am seeking assistance in investigating why my domain is being classified as malicious and how to resolve the false positive classification.

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.