Safe Links checks URLs in email, Teams messages and Office documents against known malicious links when a user clicks them, and can rewrite email links so every click goes through that check. Safe Attachments opens email attachments in a virtual environment (detonation) before delivery and quarantines the message if the file is malicious. Both are part of Microsoft Defender for Office 365. Every licensed user is covered by the Built-in protection preset policy by default, but for real hardening you should assign users to the Standard or Strict preset security policy, which rewrites URLs, blocks click-through and applies Safe Links to internal mail, and turn on Safe Attachments for SharePoint, OneDrive and Microsoft Teams.
Who this is for and what you will have
This guide is for Microsoft 365 administrators with Defender for Office 365 Plan 1 or Plan 2 (on their own or in a suite) who want to know what Safe Links and Safe Attachments actually do, which settings matter and how to deploy them without breaking mail flow. At the end you will have:
- A clear picture of which policy applies to which user.
- Standard or Strict preset policies assigned, or custom policies built with the right settings.
- Safe Attachments protection for SharePoint, OneDrive and Teams files, with downloads of infected files blocked.
- A tested configuration and a list of the problems you are most likely to see.
How the policies fit together
Order of precedence
There is no default Safe Links or Safe Attachments policy. Instead, each recipient gets the first matching policy in this order, and processing stops there:
- Strict preset security policy, if the user is assigned to it.
- Standard preset security policy, if the user is assigned to it.
- Custom policies, in priority order (0 is highest).
- Built-in protection, for everyone else who has a Defender for Office 365 licence and isn't excluded.
Because only one policy applies, the settings are not merged. If a user is in Standard, their custom policy is ignored entirely, including its Do not rewrite the following URLs list.
Built-in protection versus Standard and Strict
Built-in protection is designed to be safe to switch on for everyone. Standard and Strict are stricter. The differences that matter:
| Setting | Built-in protection | Standard and Strict |
|---|---|---|
| Safe Links for email, Teams and Office apps | On | On |
| Apply Safe Links to email sent within the organization | Off | On |
| Real-time URL scanning and wait for scan before delivery | On | On |
| Do not rewrite URLs, do checks via Safe Links API only | On (no rewriting) | Off (URLs rewritten) |
| Let users click through to the original URL | On | Off |
| Safe Attachments unknown malware response | Block | Block |
| Safe Attachments quarantine policy | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy |
Microsoft generally recommends assigning everyone to Standard or Strict rather than maintaining custom policies. Use custom policies when you need a setting the presets don't allow, such as a Do not rewrite list or Dynamic Delivery.
Safe Links in detail
When Safe Links for email is on, links in inbound messages are scanned before delivery. If rewriting is on, they are wrapped with a prefix such as https://nam01.safelinks.protection.outlook.com, so every click goes through Safe Links. If rewriting is off, Outlook for Windows, Mac and Outlook on the web call the Safe Links API at the time of click instead.
The rewriting choice matters for clients that don't support the API. A link that was clean at delivery and later weaponised is only caught on click if the client checks it, so users of third-party mail clients get click-time protection only when URLs are rewritten.
The email settings, with their PowerShell parameters:
| Portal setting | Parameter | What it does |
|---|---|---|
| On: Safe Links checks a list of known, malicious links when users click links in email. URLs are rewritten by default | EnableSafeLinksForEmail | Turns on Safe Links for email |
| Apply Safe Links to email messages sent within the organization | EnableForInternalSenders | Wraps and checks links in internal mail |
| Apply real-time URL scanning for suspicious links and links that point to files | ScanUrls | Scans suspicious links and links to downloadable files |
| Wait for URL scanning to complete before delivering the message | DeliverMessageAfterScan | Holds the message until scanning is done |
| Do not rewrite URLs, do checks via SafeLinks API only | DisableUrlRewrite | Turns off wrapping |
| Do not rewrite the following URLs in email | DoNotRewriteUrls | Exclusions from wrapping and mail-flow scanning |
Limitations to know: Safe Links doesn't work on mail-enabled public folders, supports only HTTP, HTTPS and FTP links, doesn't protect URLs in RTF (TNEF) messages and ignores S/MIME-signed messages. Links to SharePoint and OneDrive are no longer wrapped but are still processed. If another service wraps links before Defender for Office 365 sees them, Safe Links may not be able to process them.
Teams and Office apps
In Teams, Safe Links checks links in chats, group chats, channels and tabs at the time of click; URLs aren't rewritten. Turning it on or off can take up to 24 hours. Pages that need SameSite=Strict cookies may ask users to sign in again, because the Safe Links redirect is treated as a cross-site request.
In Office apps, Safe Links checks links inside documents, not in email, in current versions of Word, Excel and PowerPoint on Windows, Mac and the web, Office apps on iOS and Android, Visio on Windows, OneNote on the web, and Outlook for Windows when opening saved EML or MSG files. Users must be signed in with their work or school account and the apps must use modern authentication.
Click protection
- Track user clicks stores click data. Click events on wrapped URLs appear in the
UrlClickEventstable in advanced hunting withAppNameset toMail. - Let users click through to the original URL lets users ignore the warning page. Leave it off.
- Display the organization branding on notification and warning pages shows your organization's branding from the Microsoft 365 organization theme, which helps users recognise genuine warning pages.
The "Do not rewrite" list
Entries in Do not rewrite the following URLs aren't scanned or wrapped during mail flow but can still be blocked at the time of click, and Teams and Office web apps ignore the list. Each entry can contain up to three * wildcards. Use contoso.com/* and *.contoso.com/* together to cover a domain, all its subdomains and all paths; *.contoso.com on its own doesn't cover contoso.com. If you need a URL to be allowed everywhere, report it as clean through admin submissions and choose Allow this URL, which adds a Tenant Allow/Block List entry.
Safe Attachments in detail
Safe Attachments runs after anti-malware scanning and detonates attachments in a virtual environment in the same region as your Microsoft 365 data. Scanning typically completes within 15 minutes, sometimes longer.
Unknown malware response
| Option | What happens | When to use it |
|---|---|---|
| Off | No Safe Attachments scanning; anti-malware still runs | Only for recipients who receive mail exclusively from trusted senders |
| Monitor | Delivers the message, tracks detections; can redirect detections to an address | Evaluating impact before blocking |
| Block | Quarantines messages with malicious attachments and blocks future instances | Recommended; the value used by Built-in protection, Standard and Strict |
| Dynamic Delivery | Delivers the body at once with attachment placeholders; quarantines if malicious | Users who can't tolerate scanning delays |
Messages quarantined by Safe Attachments use the AdminOnlyAccessPolicy quarantine policy by default. Users can never release their own messages quarantined as malware or phishing by Safe Attachments; at most they can request release.
Dynamic Delivery limitations
Dynamic Delivery only works for Exchange Online mailboxes. Most PDFs and Office documents can be previewed in safe mode while scanning runs. It can't replace attachments in several cases, including messages in public folders, messages moved out of the Inbox by inbox rules, messages moved to archive folders, deleted messages, S/MIME-encrypted messages and on-premises mailboxes. If a forwarded recipient isn't covered by a Safe Attachments policy, they receive the attachment without scanning.
Password-protected attachments
When the action is Block, you can turn on Block unscanned attachments to quarantine messages with password-protected attachments that can't be detonated. If the quarantine policy allows users to release their own messages, they can release these by entering the attachment password in the Defender portal, which triggers a new scan; the password isn't stored and can only be submitted once per message. The setting is off in all presets, and it uses DefaultFullAccessWithNotificationPolicy by default.
Prerequisites
- Defender for Office 365 licences for the users you protect. Use recipient exceptions to exclude unlicensed users from custom or preset policies.
- Organization Management or Security Administrator in Email & collaboration permissions plus Organization Management in Exchange Online, or the Security Administrator Entra role.
- Exchange Online PowerShell, and SharePoint Online PowerShell for the download block (Global Administrator or SharePoint Administrator).
- An inventory of internal applications whose links might break if rewritten.
Step 1: Assign the Standard or Strict preset policy
- In the Defender portal at
https://security.microsoft.com, go to Email & collaboration > Policies & rules > Threat policies > Preset Security Policies. - Turn on Standard protection (or Strict protection) and select Manage protection settings.
- On Apply Exchange Online Protection, choose All recipients or specific users, groups or domains.
- On Apply Defender for Office 365 protection, choose the same recipients (Previously selected recipients) or only licensed users.
- Complete the impersonation pages: up to 350 users and 50 custom domains can be protected from impersonation. Your accepted domains are protected automatically.
- Review and confirm.
Almost all preset settings can't be edited. If you need different values for a group of users, leave them out of the preset and give them a custom policy.
Step 2: Create custom policies where you need them
In the portal, go to Threat policies > Safe Links (https://security.microsoft.com/safelinksv2) or Safe Attachments (https://security.microsoft.com/safeattachmentv2) and select Create. In PowerShell, each policy has two parts: the policy (settings) and the rule (recipients and priority).
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
New-SafeLinksPolicy -Name "Finance Safe Links" -EnableSafeLinksForEmail $true `
-EnableSafeLinksForOffice $true -EnableSafeLinksForTeams $true -ScanUrls $true `
-DeliverMessageAfterScan $true -EnableForInternalSenders $true -AllowClickThrough $false `
-DoNotRewriteUrls "intranet.contoso.com/*"
New-SafeLinksRule -Name "Finance Safe Links" -SafeLinksPolicy "Finance Safe Links" -SentToMemberOf "Finance" -Priority 0New-SafeAttachmentPolicy -Name "Finance Safe Attachments" -Enable $true -Action Block
New-SafeAttachmentRule -Name "Finance Safe Attachments" -SafeAttachmentPolicy "Finance Safe Attachments" -RecipientDomainIs contoso.comTwo defaults differ between the portal and PowerShell. New policies created in the portal have Do not rewrite URLs and Let users click through selected; in PowerShell, DisableUrlRewrite and AllowClickThrough default to $false. Check both after creating a policy in the portal. In custom Safe Attachments policies, the default response is Off, so set -Enable $true explicitly.
Allow up to 6 hours for a new or updated Safe Links policy to be applied. A new Safe Attachments policy typically takes about 30 minutes to take effect.
Step 3: Protect SharePoint, OneDrive and Teams files
Safe Attachments for SharePoint, OneDrive and Microsoft Teams is a global setting, not part of any policy. Built-in protection turns it on, but check it:
- On the Safe Attachments page, select Global settings.
- Turn on Turn on Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams and select Save.
Set-AtpPolicyForO365 -EnableATPForSPOTeamsODB $true
Get-AtpPolicyForO365 | Format-List EnableATPForSPOTeamsODBBy default, users can't open, move, copy or share a file detected as malicious, but they can still delete and download it. (The Share option is still available from Manage access.) Block downloads in SharePoint Online PowerShell:
Set-SPOTenant -DisallowInfectedFileDownload $trueThis applies to admins as well as users. Then create an alert for detections under Email & collaboration > Policies & rules > Alert policy > New alert policy, with category Threat management and activity Detected malware in file.
Verify the configuration
- Run
Get-SafeLinksPolicy -Identity "<Name>"; Get-SafeLinksRule -Identity "<Name>"and the matching Safe Attachments commands, and check the values and priorities. - Send a message containing
http://spamlink.contoso.comto a protected user from outside the organization and click the link. You should see a Safe Links warning page. - View the message source and confirm links are wrapped with
safelinks.protection.outlook.comif you expect rewriting. - Check the Threat protection status report for Safe Attachments and Safe Links detections, including Content > Malware for SharePoint, OneDrive and Teams files.
- Allow up to 24 hours after changing the Teams setting, then confirm with
Get-SafeLinksPolicythatEnableSafeLinksForTeamsisTruein the policy that applies to your Teams users.
Troubleshooting
A user isn't protected by the custom policy you created. They are probably in the Standard or Strict preset, which always applies first. Remove them from the preset or move the custom settings there.
Links aren't rewritten. The applicable policy has Do not rewrite URLs, do checks via SafeLinks API only selected, which is the case for Built-in protection and for new portal-created policies. Internal mail isn't wrapped unless Apply Safe Links to email messages sent within the organization is on.
An internal application link is blocked or broken. Add it to Do not rewrite the following URLs with wildcards that cover its paths. If it is still blocked at the time of click, or in Teams, use an admin submission with Allow this URL.
Mail with attachments arrives late. That is Safe Attachments detonation, typically under 15 minutes. Use Dynamic Delivery for affected users, or check that the delay isn't from another hop with message trace.
Users see attachment placeholders that never resolve. The message was moved out of the Inbox by an inbox rule, to an archive folder or to a public folder, or was deleted. Dynamic Delivery can't replace attachments in those locations, so use Block instead of Dynamic Delivery for users whose rules routinely move mail out of the Inbox.
Policy changes fail with 403 or CmdletAccessDeniedException. If your permissions are correct, Microsoft notes that some tenants need a backend RBAC configuration refresh; open a support case and reference "RBAC configuration refresh".
A malicious file in SharePoint can still be downloaded. DisallowInfectedFileDownload isn't set. Set it in SharePoint Online PowerShell.
Checklist
- Every licensed user assigned to Standard or Strict, or deliberately left on a custom policy.
- Safe Links rewriting on, internal mail covered and click-through off for all users.
- Safe Links for Teams and Office apps on.
- Safe Attachments set to Block or Dynamic Delivery, never Off, for normal users.
- Quarantine policy chosen for Safe Attachments, with notifications if users should be told.
- Global setting Turn on Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams on, and
DisallowInfectedFileDownloadset. - Alert policy for Detected malware in file routed to the security team.
- Test with
http://spamlink.contoso.comcompleted and documented.
If a compromised mailbox gets through anyway, follow the clean-up in finding malicious inbox and forwarding rules and trace the activity with Microsoft 365 audit log search.