Forum Discussion
How to send false positive?
Hi, I coded a small program which Microsoft treats as malicous. Unfortunately the Microsoft false positive submission site is not working. How can I alternatively send a false positive to Microsoft? Any help is appreciated.
1 Reply
You can use a second Microsoft submission path without weakening Defender. If your organization has Microsoft Defender for Endpoint Plan 2 or Microsoft Defender XDR, open the Defender portal and go to Investigation and response > Actions and submissions > Submissions > Files. Add the exact detected file or its hash, select Clean as the expected classification, and include the detection name, Defender platform and intelligence versions, and reproducible steps. Otherwise, use the Microsoft Security Intelligence sample-submission portal, which accepts submissions without an Endpoint Plan 2 subscription. Sign in so you can track the result. Submit the exact release binary that users receive; recompiling changes its hash. Do not create a broad antivirus exclusion while waiting. If both submission experiences fail, capture the UTC time, browser error, and submission details and open Microsoft support. Microsoft does not document an email-based malware-analysis submission route.