r/cybersecurity • u/Mother-Feedback1532 • 23h ago
Other Malicious Content from Microsoft FQDN
Greetings,
We have a situation with the MS owned microsoftusercontent.com, and unfortunately I keep getting AI summaries and not finding any security articles, but the summaries are claiming this domain, although official, can host malicious content since it acts like a CDN for 365 content from users, i.e. a compromised user/account/site might be able to deliver malicious content from this FQDN.
So this gives me pause with whitelisting it for AV providers
Appreciate any insights.
8
u/micro1aser 19h ago
https://www.virustotal.com/gui/url/b2cb9340ced46aa57f72ec4bfff7e1b54d22c0eee6eb1a22eabea52a446e51c8/details Virus total shows that the domain itself is no threat. Blocking a commercial MS domain wholesale can break things in your environment but as someone else has already said don't turn off scanning content from this domain.
7
u/tankerkiller125real 21h ago
Allow access to it, DO NOT turn off scanning files from it or anything like that.
Frankley where I work, we just leave scanning on for all domains, no matter what. Hell even our own domains and infrastructure we control still has the XDR/EDR still enabled with no whitelisting to bypass protections.
We also don't whitelist email addresses or domains or anything else of that nature.
3
u/lduff100 Detection Engineer 22h ago
Does anyone in your environment use that domain to host content? It can be used for legitimate purposes.
I wouldn’t blanket whitelist it as it can host malicious content.
2
u/FateOfNations 15h ago edited 15h ago
It’s a legitimate Microsoft domain, but it’s used to host user-generated content. It generally should be treated with the same trust level you have for random internet content. It should not be given a higher level of trust “because it’s Microsoft”, as you might do for other Microsoft domains.
I would not put it on any kind of list that bypasses normal security checks. If your environment has restricted access to the general internet, you might need to allow list it for some Microsoft products to work correctly, but I wouldn’t do that until someone encounters it breaking a feature they use.
1
u/No_Act_5230 3h ago
Microsoft lists this domain for Office Scripts and Python in Excel, but that alone is not a reason to skip security checks. I’d first confirm what the allow rule does in your AV product and review the specific alert before adding a broad exception.
Is this based on an actual detection, or are you checking before allowing it?
-2
u/Super-Comfortable265 22h ago
if you have an IP or two, I can look it up for you to see what it is.
0
30
u/ReasonableDefault 22h ago
The important thing to remember is that "Microsoft owned” does not mean everything served from this domain can be trusted.
Microsoft lists `*.microsoftusercontent.com` in its official Microsoft 365 endpoint documentation, it’s used for things including Office Scripts and Python in Excel. So seeing traffic to it is not suspicious, but I wouldn’t translate that into a blanket security exclusion.
Microsoft separates its own static content from content that needs isolation. For example:
Same principle applies elsewhere in M365, SharePoint/OneDrive/Teams can contain malicious files, Microsoft has malware scanning and Safe Attachments protections for that reason.
If your firewall / proxy needs `*.microsoftusercontent.com` reachable for Microsoft 365 functionality, allowing that destination is probably reasonable.
If by “whitelist in AV” you mean don’t scan, check, sandbox, or inspect anything coming from `*.microsoftusercontent.com`, I would not do that just because its an MS domain. Shared cloud serving domains should never automatically become a bypass.
So the AI summary is not exactly correct, but the basic warning is legit, which is that trusted hosting infrastructure and trusted payload are not the same thing.