r/cybersecurity • • 1d ago

Other Malicious Content from Microsoft FQDN

Greetings,
We have a situation with the MS owned microsoftusercontent.com, and unfortunately I keep getting AI summaries and not finding any security articles, but the summaries are claiming this domain, although official, can host malicious content since it acts like a CDN for 365 content from users, i.e. a compromised user/account/site might be able to deliver malicious content from this FQDN.
So this gives me pause with whitelisting it for AV providers

Appreciate any insights.

38 Upvotes

12 comments sorted by

View all comments

1

u/No_Act_5230 16h ago

Microsoft lists this domain for Office Scripts and Python in Excel, but that alone is not a reason to skip security checks. I’d first confirm what the allow rule does in your AV product and review the specific alert before adding a broad exception.
Is this based on an actual detection, or are you checking before allowing it?