Forum Discussion
Brok3NSpear
Apr 25, 2024Brass Contributor
Sent from Outlook for iOS links Being Quarantined in Defender
Hi,
Microsoft seem to be falsely flagging their own shortening URL for hxxps://aka.ms/o0ukef as High Confidence Phishing
This is the link that is created in emails when a user sends an email from Outlook for iOS
This is causing a lot of emails to be blocked and sent to the Quarantine queue.
Can someone at MS take a look and get this addressed.
- UrjaGandhiMicrosoftSummary: Recently, Microsoft Defender for Office 365 observed false positives from heuristic-based detections related to URLs targeting fake Microsoft notification emails, e.g. Password expiry notifications. These detections are used to target the ever-changing email threat landscape and adjust to new tactics and techniques by various threat actors. These specific detections have been adjusted and the false positive issue has been mitigated. Furthermore, Microsoft Defender for Office 365 has implemented a long-term solution to handle such aka.ms links in a more robust fashion.
Thanks,
Microsoft Defender for Office 365 Product Group- its_Tricky83Copper ContributorThe issue is occurring again and causing massive impact!
Yesterday, today and ongoing we are suddenly seeing any emails that contain the link https://aka.ms/o0ukef being quarantined as 'High Confidence Phish'.- Brok3NSpearBrass Contributor
Haven't started to see this yet again in our tenant (UK) but will keep an eye out for it.
Thanks for the heads up
UrjaGandhi FYI for new events being reported by users