Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
Microsoft Defender for Cloud: URL classification issue causing service access disruption — Urgent investigation needed
Problem description
I am experiencing an issue where URLs under my custom domain are being classified as malicious by Microsoft Defender's Safe Links feature, leading to access disruptions for my production service. The URLs work normally outside of Microsoft products, but within Microsoft applications, they are flagged as malicious.
Environment
The affected environment involves a production service accessed via URLs on a custom domain, with the issue related to Safe Links URL reputation classification. Specific resource types, regions, or subscription details are not provided.
What I've already tried
I have reviewed the case details and attempted to understand the cause of the false-positive URL classification. The case documentation indicates that the issue is a Safe Links false positive, and I have reviewed public Safe Links documentation on URL exceptions and submitting URLs for review. No specific troubleshooting steps or configuration changes have been documented or confirmed in the case record.
Current status
The issue persists since the initial report on October 1, 2026, with URLs being flagged as malicious, impacting customer access to the service. I am seeking assistance in investigating why my domain is being classified as malicious and how to resolve the false positive classification.