Microsoft Defender for Office 365
Email and collaboration

Safe Links About

In brief

Updated Microsoft Defender documentation in defender-office-365/safe-links-about.md.

What Defender admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

URLs in Teams are checked against a list of known malicious links when the protected user clicks the link (time-of-click protection). URLs aren't rewritten. If a link is found to be malicious, users have the following experiences:

  • If the link was clicked in a Teams conversation, group chat, or from channels, the warning page as shown in the screenshot appears in the default web browser.
  • If the link was clicked from a pinned tab, the warning page appears in the Teams interface within thata new browser tab. The option to open the link in a web browser is disabled for security reasons.
  • Depending on how the Let users click through to the original URL setting in the policy is configured, the user is or isn't allowed to click through to the original URL (Continue anyway (not recommended) in the screenshot). We recommend that you don't select the Let users click through to the original URL setting so users can't click through to the original URL.

If the user who sent the link isn't protected by a Safe Links policy where Teams protection is turned on, the user is free to click through to the original URL on their computer or device.