Microsoft defender blocking legitimate urls

Suyash1590 1 Reputation point
2021-07-29T18:17:45.023+00:00

I want to report URLs for re-evaluation as Microsoft Defender is blocking them on our customer endpoints with the message in the screenshot attached

URLs include:
a) live-lia-pushy-service-v2.euw1.prod.hosted.lithcloud.com
b) live-lia-pushy-service-v2.euw1.stage.hosted.lithcloud.com

These URLs are associated with one of the products which our customer is using and these are completely safe from the security point of view as no other threat intelligence feed has marked them malicious.

Although the URLs can be whitelisted at the customer level, we want to get them whitelisted at a global level so that other customers using Microsoft defender in their environment do not face the same issue.

Can someone help me in this issue?119165-screenshot-20210729-232745-855.png

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
{count} votes

2 answers

Sort by: Most helpful
  1. bob 5 Reputation points
    2023-01-25T17:23:44.47+00:00

    Microsoft has done this twice to us. The first time it took 36 hours for MS to respond and remedy. This time we are on day 4 without a response or acknowledgement.

    We are a private, licensed, enterprise software web app (not a "website"), where each customer gets their own personalized wildcard URL and a link to the customer's Okta Single Sign site where their users are required to go to login to our site, i.e. it is a link on our login page. Somehow, this obvious link to an Okta URL and an Okta site was deemed to be dangerous enough that Microsoft was compelled to blindly accuse our company of being dangerous and of phishing without any investigation or opportunity to remedy.

    By contrast, Netcraft, Firefox, Chrome, and our host were responsive and promptly removed this improper block within hours. Microsoft did not, and is not, responding or remedying the situation after days. It is a black-hole process.

    Microsoft has globally labeled our business as being dangerous and accused us of being a phishing site while hiding under the covers of "reported to Microsoft." This is like being put in jail because some third party said you looked like a criminal due to the shirt you were wearing, then having the jailer publish accusations worldwide that you are dangerous and may be committing crimes while not talking to you or investigating the matter for days, all while you slowly lose your livelihood and business.

    Microsoft apparently believes it is OK to defame orgs and block their businesses based on hearsay, without any communication, investigation, or application of common sense, and then provides no mechanism or opportunity for support or remedy other than a generic webform that isn't even designed for web apps for which there is no tracking number, ID, or alternative method of communications or recourse.

    Microsoft's statements that "These reports are verified by our support team and mistakes are corrected" and "Microsoft Defender SmartScreen has a built-in, web-based feedback system in place to help customers and website owners report any potential false warnings as quickly as possible" is misleading at best, and it does not explain that this process may or may not happen, does not address web applications at all, nor does it explain that "quickly as possible" really means someday or whenever Microsoft feels like it.

    As a former CIO, CISO, and as a CEO, and as a 30-year advocate of Microsoft, and after speaking with many colleagues, I find this process of "prove your innocence" and its deaf ears of after the fact justice appalling, shameful, and intentionally harmful. Lacking further clarity and support, we face no choice but to turn this over to counsel.

    1 person found this answer helpful.
    0 comments No comments

  2. Miles 1,281 Reputation points
    2021-07-30T05:03:53.767+00:00

    Hi

    Then we could immediately submit a request for a correction. Microsoft Defender SmartScreen has a built-in, web-based feedback system in place to help customers and website owners report any potential false warnings as quickly as possible. In Windows Internet Explorer, from a red warning, click More information then Report that this site contains no threats. This will take you to a feedback page where you can indicate you are a site owner or representative. Follow the instructions and provide the information on this site to submit a site for review.

    To report feedback from the Internet Explorer Download Manager, Right-click on the blocked download and choose Report that this file is safe. This will take you to the feedback page.

    Once a dispute is submitted, a team of graders inspects the site in question. All disputes should be submitted through the website reporting process to ensure the quickest resolution.

    In Microsoft Edge, click More information then Report that this site does not contain threats.

    For more information, we could refer to this article on Microsoft Defender SmartScreen Frequently Asked Questions:
    https://feedback.smartscreen.microsoft.com/smartscreenfaq.aspx

    Hope these information could bring you some help.
    Best Regards


    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.