Skip to content

Windows Defender blocks Connect-SPOService, False positive? Detected: Trojan:Script/Wacatac.H!ml #10811

@nmcgregor23

Description

@nmcgregor23

Target SharePoint environment

SharePoint Online

What SharePoint development model, framework, SDK or API is this about?

SharePoint REST API

Developer environment

Windows

What browser(s) / client(s) have you tested

  • 💥 Internet Explorer
  • 💥 Microsoft Edge
  • 💥 Google Chrome
  • 💥 FireFox
  • 💥 Safari
  • mobile (iOS/iPadOS)
  • mobile (Android)
  • not applicable
  • other (enter in the "Additional environment details" area below)

Additional environment details

Image Image

Multi-Geo, SharePoint site is in France.

Describe the bug / error

When connecting to the sharepoint admin site using Connect-SPOService, Defender flags it as a Trojan.

Image

Multi-Geo, this site is in France.
$AdminSite = "https://Contosofra-admin.sharepoint.com/"
Connect-SPOService -Url $adminSite

Steps to reproduce

  1. Run Connect-SPOService
  2. Login with Account
  3. Receive this error message
Image
  1. Select Yes
  2. Defender blocks it as a Trojan

Expected behavior

Successfully log into Sharepoint

Metadata

Metadata

Assignees

Labels

sharepoint-developer-supportsharepoint-developer-supporttype:bug-suspectedSuspected bug (not working as designed/expected). See “type:bug-confirmed” for confirmed bugs.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions