Microsoft 365 Safe Links setup — enable Safe Links in Defender for Office 365
Enable Safe Links in Microsoft Defender for Office 365 by creating a Safe Links policy in the Microsoft 365 Defender portal, assigning it to your users or groups, and testing with a benign URL; a basic setup usually takes under 30 minutes for a small or mid-sized tenant.
Restricting Safe Links to Exchange only
What happens: Many admins enable Safe Links for Exchange Online and assume URLs in Teams chat, SharePoint and OneDrive are covered. In reality Safe Links is a cross-product feature but it only protects locations you explicitly include when you create the policy. If you limit protection to Exchange, users still receive live URLs in Teams, SharePoint and Office documents without time-of-click checks.
How this breaks workflows and risk posture:
- Phishing links inside Teams messages or a SharePoint page can go straight to users without rewrites or scanning.
- Document collaboration (OneDrive/SharePoint) can be a vector for weaponised links shared inside files.
Fix in practice: When you create the policy, select the appropriate Urls and attachments locations and enable protection for Exchange, Teams, and SharePoint/OneDrive. Test with a harmless URL across each app. If you need help mapping which workloads your users use most, consider contacting Microsoft 365 support for business to review your tenant settings.
Leaving the default Safe Links policy unchanged
What happens: The default Safe Links policy is very broad and conservative. Leaving it untouched often means either overly aggressive blocking for critical services, or conversely, not applying the tougher custom rules that protect executives or sensitive departments. Default policies are a starting point, not a production rulebook.
Common side-effects:
- False positives that interrupt sales or supplier communication because necessary partner URLs are blocked.
- Over-permissive allowances where legacy exceptions exist but should be reassessed.
Fix in practice: Duplicate the default policy and create targeted policies for groups with different risk profiles (finance, HR, exec). Use policy priorities rather than relying on the blanket default. Keep a short whitelist of verified vendor domains and log exceptions — review these quarterly.
Disabling time-of-click scanning or relying on static URL lists
What happens: Some tenants turn off time-of-click scanning to reduce perceived latency or to avoid altering URLs in emails. Time-of-click scanning is the core benefit of Safe Links: it checks a URL at the moment a user clicks, catching credential-stealing or malicious pages that appeared after delivery. Relying on static URL blocklists misses fast-moving campaigns.
Practical consequences:
- Links that were safe at delivery can become malicious later; static lists won’t catch that.
- Attackers use URL shorteners and redirect chains to evade blocklists; a time-of-click check follows the redirect chain and evaluates the final destination.
Fix in practice: Ensure the policy has time-of-click scanning enabled and that rewriting of URLs is active for email and Office documents. Balance user experience by excluding internal trusted services rather than disabling scanning entirely.
Testing Safe Links only with admins
What happens: IT teams commonly test with global admins or a small security pilot group and declare success. Admins typically have elevated access, different routing and may not use the same external services as regular staff. That leaves everyday users exposed to usability surprises or gaps that admins never encounter.
How to test properly:
- Create pilot groups that mirror real teams — sales, accounts, operations.
- Simulate typical user behaviours: opening documents from SharePoint, clicking links in Teams, and receiving calendar invites with links.
- Track blocked/rewritten clicks and gather user feedback for two weeks before a full rollout.
Also include a non-admin account for testing supplier portals and payment systems; some finance platforms use complex redirect flows that need explicit allowance rules.
Cost of leaving these Safe Links mistakes unfixed
If you leave these errors in place you trade predictable protection for intermittent coverage: successful phishing and supply-chain link attacks, disrupted business processes from over-blocking, and higher incident response costs. Fixes are usually configuration and testing work rather than licensing changes, but the hidden cost is downtime and reputational risk when a user clicks a malicious link. Tie your policy reviews to your incident metrics and schedule a quarterly policy audit to keep protection aligned with business use.
Related reading
- our microsoft 365 support for business guide
- Microsoft 365 security audit service: what UK SMEs need to know
- Is Microsoft 365 Threat Protection Enough?
- Cost of Microsoft 365 managed services — a practical guide for UK businesses
- Microsoft 365 backup service: a straightforward guide for UK businesses
FAQ
How long does a typical Safe Links setup take for a 50-person company?
A basic Safe Links policy can be created and applied in under 30 minutes, but allow 1–2 days for staged testing across Teams, SharePoint and Exchange and to iterate whitelist exceptions if needed.
Do I need an extra licence to use Safe Links in Microsoft 365?
Safe Links is included with Microsoft Defender for Office 365 plans; check your tenant’s licence details in the Microsoft 365 admin centre — many business plans require Defender for Office 365 P1 or equivalent add-on.
Which workloads should Safe Links cover to be effective in a UK office environment?
Include Exchange Online, Teams chat and channel messages, and SharePoint/OneDrive document links; exclude only fully internal, verified services after validation to avoid user disruption.
Who should own quarterly Safe Links policy reviews?
Assign ownership to the person responsible for IT security or the external support partner you use; reviews should be every three months or after any significant change to supplier platforms.







