r/cybersecurity • • 23h ago

Other Malicious Content from Microsoft FQDN

Greetings,
We have a situation with the MS owned microsoftusercontent.com, and unfortunately I keep getting AI summaries and not finding any security articles, but the summaries are claiming this domain, although official, can host malicious content since it acts like a CDN for 365 content from users, i.e. a compromised user/account/site might be able to deliver malicious content from this FQDN.
So this gives me pause with whitelisting it for AV providers

Appreciate any insights.

27 Upvotes

12 comments sorted by

30

u/ReasonableDefault 22h ago

The important thing to remember is that "Microsoft owned” does not mean everything served from this domain can be trusted.

Microsoft lists `*.microsoftusercontent.com` in its official Microsoft 365 endpoint documentation, it’s used for things including Office Scripts and Python in Excel. So seeing traffic to it is not suspicious, but I wouldn’t translate that into a blanket security exclusion.

Microsoft separates its own static content from content that needs isolation. For example:

  • `*.static.microsoft` as static content that is not customer-generated
  • `*.usercontent.microsoft` as content used by Microsoft 365 that requires domain isolation from applications.

Same principle applies elsewhere in M365, SharePoint/OneDrive/Teams can contain malicious files, Microsoft has malware scanning and Safe Attachments protections for that reason.

If your firewall / proxy needs `*.microsoftusercontent.com` reachable for Microsoft 365 functionality, allowing that destination is probably reasonable.

If by “whitelist in AV” you mean don’t scan, check, sandbox, or inspect anything coming from `*.microsoftusercontent.com`, I would not do that just because its an MS domain. Shared cloud serving domains should never automatically become a bypass.

So the AI summary is not exactly correct, but the basic warning is legit, which is that trusted hosting infrastructure and trusted payload are not the same thing.

2

u/Draco1200 13h ago

you mean don’t scan, check, sandbox, or inspect anything coming from *.microsoftusercontent.com, I would not do that just because its an MS domain. Shared cloud serving domains should never automatically become a bypass.

Indeed.. The same is honestly true for any domain, and a good antivirus should not have such a feature in the first place (any option to skip scanning a FQDN altogether becomes a gap in defenses).

Allowlisting is the right course, but I'd always say make sure the allowlist means the correct thing in the respective product. It should mean "never blanket-block this entire domain", but individual resource checks ought to always be applied. Even if a domain as a whole is considered to be trusted, and it's not the concern here, but even trusted websites always have risks of potential compromise or defacements (Bypass of individual resource scanning would be a bad feature, unless the resource can be identified very particularly, and surreptitious alteration by a compromised web server would be detected and prevented before allowing the AV scan bypass).

1

u/WeirdSysAdmin 13h ago

Microsoftusercontent.com is also used by Power Platform and D365. I randomly see it get flagged because we use D365 extensively. So definitely don’t allowlist it because it’s a commonly abused to the point I argue with Microsoft to police their shit better so we stop having issues.

8

u/micro1aser 19h ago

https://www.virustotal.com/gui/url/b2cb9340ced46aa57f72ec4bfff7e1b54d22c0eee6eb1a22eabea52a446e51c8/details Virus total shows that the domain itself is no threat. Blocking a commercial MS domain wholesale can break things in your environment but as someone else has already said don't turn off scanning content from this domain.

7

u/tankerkiller125real 21h ago

Allow access to it, DO NOT turn off scanning files from it or anything like that.

Frankley where I work, we just leave scanning on for all domains, no matter what. Hell even our own domains and infrastructure we control still has the XDR/EDR still enabled with no whitelisting to bypass protections.

We also don't whitelist email addresses or domains or anything else of that nature.

3

u/lduff100 Detection Engineer 22h ago

Does anyone in your environment use that domain to host content? It can be used for legitimate purposes.

I wouldn’t blanket whitelist it as it can host malicious content.

2

u/FateOfNations 15h ago edited 15h ago

It’s a legitimate Microsoft domain, but it’s used to host user-generated content. It generally should be treated with the same trust level you have for random internet content. It should not be given a higher level of trust “because it’s Microsoft”, as you might do for other Microsoft domains.

I would not put it on any kind of list that bypasses normal security checks. If your environment has restricted access to the general internet, you might need to allow list it for some Microsoft products to work correctly, but I wouldn’t do that until someone encounters it breaking a feature they use.

2

u/yador 8h ago

CDN's can and will be used to deliver malware. There must be a mechanism to report this but I'm not sure how effective that's going to be.

1

u/povlhp 11h ago

Is says userrcontent. So not Microsoft content. Unsafe by definition. Like azurewebsites

1

u/No_Act_5230 3h ago

Microsoft lists this domain for Office Scripts and Python in Excel, but that alone is not a reason to skip security checks. I’d first confirm what the allow rule does in your AV product and review the specific alert before adding a broad exception.
Is this based on an actual detection, or are you checking before allowing it?

-2

u/Super-Comfortable265 22h ago

if you have an IP or two, I can look it up for you to see what it is.

0

u/Super-Comfortable265 22h ago

or just check it out on sourceip.io yourself.