Forum Discussion

Brok3NSpear's avatar
Brok3NSpear
Brass Contributor
Apr 25, 2024

Sent from Outlook for iOS links Being Quarantined in Defender

Hi,

 

Microsoft seem to be falsely flagging their own shortening URL for hxxps://aka.ms/o0ukef as High Confidence Phishing

 

This is the link that is created in emails when a user sends an email from Outlook for iOS

 

 

This is causing a lot of emails to be blocked and sent to the Quarantine queue.

 

Can someone at MS take a look and get this addressed.

  • Summary: Recently, Microsoft Defender for Office 365 observed false positives from heuristic-based detections related to URLs targeting fake Microsoft notification emails, e.g. Password expiry notifications. These detections are used to target the ever-changing email threat landscape and adjust to new tactics and techniques by various threat actors. These specific detections have been adjusted and the false positive issue has been mitigated. Furthermore, Microsoft Defender for Office 365 has implemented a long-term solution to handle such aka.ms links in a more robust fashion.

    Thanks,
    Microsoft Defender for Office 365 Product Group
    • its_Tricky83's avatar
      its_Tricky83
      Copper Contributor
      The issue is occurring again and causing massive impact!
      Yesterday, today and ongoing we are suddenly seeing any emails that contain the link https://aka.ms/o0ukef being quarantined as 'High Confidence Phish'.
      • Brok3NSpear's avatar
        Brok3NSpear
        Brass Contributor

        its_Tricky83 

         

        Haven't started to see this yet again in our tenant (UK) but will keep an eye out for it.

         

        Thanks for the heads up

         

        UrjaGandhi FYI for new events being reported by users

         

         

Resources