Defender SmartScreen claiming internal SharePoint/OneDrive site was reported as unsafe

%3CLINGO-SUB%20id%3D%22lingo-sub-2212288%22%20slang%3D%22en-US%22%3EDefender%20SmartScreen%20claiming%20internal%20SharePoint%2FOneDrive%20site%20was%20reported%20as%20unsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2212288%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe've%20had%20a%20couple%20of%20users%20experience%20SmartScreen%20blocking%20O365%20file%20sharing%20links%20(SharePoint%2FOneDrive)%20sent%20to%20and%20from%20users%20on%20our%20own%20domain.%20Here%20is%20what%20they%20receive%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AndrewSAIF_0-1615835621217.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F263834iB7174B8F23D50174%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22AndrewSAIF_0-1615835621217.png%22%20alt%3D%22AndrewSAIF_0-1615835621217.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20link%20is%20just%20an%20xlsx%20file%20that%20is%20parked%20on%20a%20user's%20OneDrive.%20I've%20inspected%20the%20file%2C%20and%20it%20does%20not%20contain%20any%20active%20content%20that%20could%20be%20construed%20as%20malicious.%20Furthermore%2C%20the%20user%20created%20a%20second%20link%20to%20the%20same%20document%2C%20which%20is%20not%20blocked%20by%20SmartScreen.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20users%20themselves%20claim%20that%20they%20did%20not%20report%20the%20link%20as%20malicious%20(of%20course%2C%20users%20never%20lie%2C%20right%3F).%20Based%20on%20what%20I%20am%20reading%2C%20though%2C%20SmartScreen%20will%20display%20this%20message%20whether%20a%20person%20reported%20it%20or%20Microsoft's%20algorithms%20have%20flagged%20it%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-security-smartscreen%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Edge%20support%20for%20Microsoft%20Defender%20SmartScreen%20%7C%20Microsoft%20Docs%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EI%20realize%20I%20can%20AllowList%20our%20SharePoint%20domain%20for%20SmartScreen%2C%20but%20I%20don't%20really%20want%20to%20give%20up%20the%20protection%20entirely.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EWe've%20had%20Edge%20deployed%20companywide%20since%20last%20August%2C%20and%20have%20had%20no%20such%20reports%20until%20now.%20We%20have%20around%201100%20active%20users%20and%20many%20of%20them%20use%20the%20O365%2FOneDrive%2FSharePoint%20ecosystem%20with%20great%20frequency.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20are%20a%20few%20things%20I%20don't%20like%20about%20this%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EThe%20ambiguity%20of%20the%20message%20(this%20site%20has%20been%20reported)%20makes%20it%20unclear%20whether%20this%20is%20user%20error%20or%20a%20false%20positive%20on%20Microsoft's%20part.%20If%20I%20could%20be%20certain%20that%20a%20human%20being%20reported%20the%20site%2C%20I'd%20know%20for%20a%20fact%20that%20it%20was%20one%20of%20the%20people%20with%20rights%20to%20the%20file%2C%20and%20could%20easily%20find%20and%20educate%20that%20person.%20If%20I%20can't%2C%20it%20doesn't%20exactly%20inspire%20confidence%20in%20the%20detection%20algorithm%20for%20the%20affected%20users.%3C%2FLI%3E%3CLI%3ERegardless%20of%20whether%20it%20is%20a%20false%20positive%20or%20an%20erroneous%20report%2C%20there%20does%20not%20appear%20to%20be%20an%20easy%20way%20to%20cancel%20the%20warning%20on%20our%20end.%20There%20is%20a%20'this%20site%20is%20not%20malicious'%20feature%20that%20allows%20us%20to%20fill%20out%20a%20form%2C%20but%20submitting%20it%20doesn't%20immediately%20cancel%20the%20warning.%20This%20makes%20sense%20for%20a%20random%20false-positive%20site%20out%20on%20the%20wild%2C%20wooly%20Internet%2C%20but%20only%20our%20users%20have%20access%20to%20our%20SharePoint.%20If%20someone%20uploaded%20something%20malicious%2C%20we'd%20have%20several%20other%20problems%20to%20address.%26nbsp%3B%3C%2FLI%3E%3CLI%3EUsers%20can%20still%20access%20the%20same%20file%20through%20the%20'Shared'%20tab%20in%20OneDrive.%20They%20only%20get%20blocked%20trying%20to%20open%20the%20link%20from%20their%20Outlook.%20Makes%20the%20protection%20seem%20arbitrary.%26nbsp%3B%3C%2FLI%3E%3C%2FUL%3E%3CP%3EHas%20anyone%20else%20run%20into%20this%20behavior%20in%20your%20organization%3F%20I%20would%20be%20interested%20to%20know%20if%20there%20are%20other%20options%20for%20dealing%20with%20this%20besides%20having%20folks%20re-share%20everything%20or%20sending%20a%20report%20to%20MS%20and%20hoping%20it%20gets%20approved%20on%20their%20side.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EAndrew%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2228720%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20SmartScreen%20claiming%20internal%20SharePoint%2FOneDrive%20site%20was%20reported%20as%20unsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2228720%22%20slang%3D%22en-US%22%3EHad%20the%20exact%20same%20issue%20above%20user%20or%20contributor%20has%20reported%20it%20and%20no%20matter%20how%20many%20false%20reports%20to%20Microsoft%20it%20doesn't%20get%20unblocked.%3CBR%20%2F%3EWhitelisting%20internally%20is%20an%20option%20but%20not%20when%20collaborating%20externally%20to%20clientele.%3CBR%20%2F%3E%3CBR%20%2F%3EDid%20you%20get%20a%20resolution%20to%20this%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2229823%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20SmartScreen%20claiming%20internal%20SharePoint%2FOneDrive%20site%20was%20reported%20as%20unsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2229823%22%20slang%3D%22en-US%22%3ESmartScreen%20filter%20won't%20just%20block%20a%20website%20based%20on%20report%2C%20it%20has%20method%20to%20investigate%20and%20when%20report%20is%20accurate%2C%20then%20block%20it.%20It%20will%20also%20do%20it%20in%20automatic%20way.%3CBR%20%2F%3EWhen%20you%20see%20this%20report%2C%20in%20case%20you%20are%20the%20owner%20of%20the%20domain%2C%20you%20could%20report%20it%20as%20website%20owner%20and%20ask%20to%20remove%20it%20from%20the%20list.%20Users%20also%20could%20report%20it%20as%20safe%20and%20Microsoft%20SmartScreen%20filter%20team%20shall%20review%20and%20when%20they%20detect%20it%20as%20safe%2C%20then%20they%20will%20remove%20the%20flag%20for%20unsafe.%3C%2FLINGO-BODY%3E
Contributor

Hello,

 

We've had a couple of users experience SmartScreen blocking O365 file sharing links (SharePoint/OneDrive) sent to and from users on our own domain. Here is what they receive:

AndrewSAIF_0-1615835621217.png

 

The link is just an xlsx file that is parked on a user's OneDrive. I've inspected the file, and it does not contain any active content that could be construed as malicious. Furthermore, the user created a second link to the same document, which is not blocked by SmartScreen. 

 

The users themselves claim that they did not report the link as malicious (of course, users never lie, right?). Based on what I am reading, though, SmartScreen will display this message whether a person reported it or Microsoft's algorithms have flagged it:
Microsoft Edge support for Microsoft Defender SmartScreen | Microsoft Docs

I realize I can AllowList our SharePoint domain for SmartScreen, but I don't really want to give up the protection entirely. 

We've had Edge deployed companywide since last August, and have had no such reports until now. We have around 1100 active users and many of them use the O365/OneDrive/SharePoint ecosystem with great frequency. 

 

There are a few things I don't like about this:

 

  • The ambiguity of the message (this site has been reported) makes it unclear whether this is user error or a false positive on Microsoft's part. If I could be certain that a human being reported the site, I'd know for a fact that it was one of the people with rights to the file, and could easily find and educate that person. If I can't, it doesn't exactly inspire confidence in the detection algorithm for the affected users.
  • Regardless of whether it is a false positive or an erroneous report, there does not appear to be an easy way to cancel the warning on our end. There is a 'this site is not malicious' feature that allows us to fill out a form, but submitting it doesn't immediately cancel the warning. This makes sense for a random false-positive site out on the wild, wooly Internet, but only our users have access to our SharePoint. If someone uploaded something malicious, we'd have several other problems to address. 
  • Users can still access the same file through the 'Shared' tab in OneDrive. They only get blocked trying to open the link from their Outlook. Makes the protection seem arbitrary. 

Has anyone else run into this behavior in your organization? I would be interested to know if there are other options for dealing with this besides having folks re-share everything or sending a report to MS and hoping it gets approved on their side. 

Andrew

4 Replies
Had the exact same issue above user or contributor has reported it and no matter how many false reports to Microsoft it doesn't get unblocked.
Whitelisting internally is an option but not when collaborating externally to clientele.

Did you get a resolution to this?
SmartScreen filter won't just block a website based on report, it has method to investigate and when report is accurate, then block it. It will also do it in automatic way.
When you see this report, in case you are the owner of the domain, you could report it as website owner and ask to remove it from the list. Users also could report it as safe and Microsoft SmartScreen filter team shall review and when they detect it as safe, then they will remove the flag for unsafe.

@Reza_Ameri 

Been reporting everyday for 4 months  with no resolution.

@Synergy1001 

Check with the host and may be there is malware in the host and ask them to investigate for security issue. May be it contains some malicious contents.