We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Safe Links
Microsoft Defender for Office 365 Safe Links, UAE

Turning off URL rewriting looks tidy. Microsoft own documentation shows the user who gets phished because of it.

Safe Links scans and rewrites URLs in inbound mail during mail flow, then verifies them again at time of click in email, Teams and supported Office apps. The configuration choices matter more than the switch: there is no default policy, several message types are not covered at all, and the API-only mode has a documented failure case.

Book a Safe Links configuration reviewSee what it does not cover
Microsoft Defender for Office 365 Safe Links for UAE organisations
  • Time of clickNot just at delivery
  • Mail, Teams, OfficeThree separate policy settings
  • No default policyBuilt-in protection preset covers the gap
  • Priority orderedFirst matching policy wins, then stops
What it does and does not do

Eight things that decide whether Safe Links is actually protecting your people.

Microsoft describes Safe Links as providing URL scanning and rewriting of inbound email during mail flow, plus time-of-click verification of URLs and links in email, Teams and supported Office 365 apps, in addition to regular anti-spam and anti-malware protection. The value is in the second scan, at click, because that is when a link that was clean on delivery has become malicious.

Time-of-click verification, which is the whole point

A link is checked when the user clicks it, not only when the message arrived. Attackers know this, which is why campaigns increasingly deliver a clean URL and weaponise the destination hours later. Microsoft states that as long as Safe Links protection is on, URLs are scanned prior to delivery regardless of whether they are rewritten, and if rewriting is enabled they are scanned again on click.

There is no default policy, but there is built-in protection

Microsoft states plainly that although there is no default Safe Links policy, the Built-in protection preset security policy provides Safe Links protection in email, Teams and files in supported Office apps to all recipients for customers with at least one Defender for Office 365 licence. So doing nothing is not the same as having nothing, but it is also not the same as having a deliberate configuration.

Rewriting versus API-only, and the documented consequence

The Do not rewrite URLs setting checks via the Safe Links API instead of wrapping. Microsoft publishes the failure case: a user clicks a link in an alternative email client that does not support the API, the link was legitimate on delivery and weaponised later, and the published result is that the user is phished, because the link was not malicious on delivery. Tidy URLs, real exposure.

Teams is a separate setting, and it does not rewrite

Teams protection is enabled separately in the policy and covers desktop, web, and Android and iOS mobile apps. URLs are not rewritten, they are checked at time of click against a list of known malicious links. Two operational details: enabling or disabling can take up to 24 hours to take effect, and if the sender is not covered by a Teams-enabled policy they can still click through to the original URL themselves.

Office apps protection checks documents, not email

Microsoft is precise: Safe Links protection for Office apps checks links in Office documents, not links in email messages, though it can check links in attached Office documents once the document is opened. It requires supported apps configured for modern authentication and users signed in with work or school accounts, and Microsoft notes it may take several seconds at the start of each session to verify availability.

Internal mail is not covered unless you say so

The Apply Safe Links to email messages sent within the organization setting controls whether messages between internal senders and internal recipients in the same Exchange Online organisation are scanned. Microsoft recommended value is on. Since compromised internal mailboxes are how most lateral phishing works in the UAE market, leaving this off removes protection from the most credible attack.

Policy priority, and processing stops at the first match

Microsoft states no two policies can have the same priority, and processing stops after the first policy is applied, meaning the highest priority policy for that recipient. Standard and Strict preset policies are always applied before custom policies, and Built-in protection is always applied last. A user in several policies gets exactly one, including exactly one do-not-rewrite list.

Several message types are simply not covered

Microsoft lists them: Safe Links does not work on mail-enabled public folders, supports only HTTP, HTTPS and FTP link formats, does not protect URLs in rich text format messages also known as TNEF, and ignores S and MIME signed messages. It also notes that using another service to wrap links before Defender for Office 365 might prevent Safe Links from processing them at all.

The configuration argument we have most often

Users hate wrapped URLs. Microsoft published what happens when you stop wrapping them.

The request to turn off URL rewriting almost always comes from the business, and the counter-argument is in Microsoft own scenario table rather than in our opinion.

  • The published scenario, quoted: an IT department configured Safe Links not to rewrite URLs and to check via API only. The user clicks a link in an alternative email client that does not support the Safe Links API. The link was legitimate on delivery but was later weaponised.
  • The published outcome, quoted: the user is phished, because the link was not malicious on delivery, so Safe Links did not detect it. The API call that would have caught it at click never happened, because that client does not support it.
  • API-only checking works in supported versions of Outlook on Windows, Mac and Outlook on the web. It does not help in clients outside that set, which in most organisations includes at least one team using something else.
  • There is a middle path worth knowing about: rewriting is still enabled, and a well-maintained do not rewrite list covers the internal URLs users complain about most. That preserves click-time protection where it matters while removing the cosmetic irritation.
Ask us to review your Safe Links policy
How we approach it

Four things a Safe Links review nearly always finds.

This is a feature almost every Microsoft 365 customer in the UAE already has and almost nobody has looked at since it was switched on. The review is short and the findings are consistent.

Internal mail is not being scanned

The setting to apply Safe Links to messages sent within the organisation is separate and frequently left off, even though Microsoft recommends it on. Given that lateral phishing from a compromised internal mailbox is the most credible attack most UAE organisations face, this is the highest-value single change in most reviews.

Users can click through the warning page

The Let users click through to the original URL setting controls whether a user can proceed past a malicious website warning. Microsoft recommended value is not selected, meaning users cannot proceed. In practice it is often on, which turns a block into a speed bump for exactly the people most likely to ignore it.

The policy priority order does not do what people think

Processing stops at the first matching policy, Standard and Strict presets always come before custom policies, and Built-in protection is always last. That means a carefully written custom policy can never apply to someone already covered by a preset, and only one do not rewrite list ever takes effect per user. Both surprise people regularly.

The do not rewrite list has wildcards that do not do what was intended

Microsoft is explicit that an entry for a subdomain wildcard does not cover the bare domain, so covering both needs two entries, and that up to three wildcards are allowed per entry. Lists written years ago routinely contain entries that exclude nothing, or exclude far more than anybody intended, and nobody has re-read them since.

Where this matters most

Six UAE situations where the Safe Links configuration is worth an hour.

Safe Links is not a product you buy, it is a set of decisions inside one you already own. The situations below are where those decisions have the largest consequence.

A financial firm targeted by payment redirection fraud

Business email compromise in the UAE frequently runs through a compromised supplier or internal mailbox rather than an obvious external sender. Scanning internal to internal mail, keeping click-through off, and enabling real-time scanning of links that point to files together address the delivery mechanism that these campaigns actually use.

A group that recently consolidated tenants

Consolidation leaves layered policies with overlapping recipient filters and priorities nobody set deliberately. Because processing stops at the first matching policy, half the estate can be running on a policy nobody remembers writing. Rationalising priority order is usually the fastest way to make coverage match intent.

An organisation running a third-party email security gateway

Microsoft notes that using another service to wrap links before Defender for Office 365 might prevent Safe Links from processing them, including wrapping, detonating or otherwise validating the link. Where two products both rewrite, one of them is doing nothing, and knowing which is a fifteen minute check with real consequences.

A business that has moved most communication into Teams

Teams protection is a separate setting, does not rewrite URLs, and takes up to 24 hours to take effect when changed. There is also the sender caveat: if the person who sent the link is not covered by a Teams-enabled policy, they can still click through to the original URL themselves, which matters for shared and external-facing teams.

An operator whose users complain about wrapped links

The request to disable rewriting is almost always driven by the appearance of the wrapped URL rather than by any functional problem. A maintained do not rewrite list covering internal services such as intranet and line of business URLs solves the complaint without moving to API-only checking and its documented failure case.

A school or university with a diverse mail client estate

API-only checking works in supported Outlook versions on Windows, Mac and the web. Education estates in particular carry a long tail of other clients, which is exactly the population the published failure scenario describes. Where client diversity is high, rewriting is the safer default rather than the inconvenient one.

Three positions

How UAE organisations configure link protection.

The middle column is the common one: licensed, enabled, never reviewed since the tenant was built, and quietly missing internal mail and Teams.
Inbound email links checked at click
Reviewed and tunedYes
On, never reviewedUsually
Built-in protection onlyYes
Internal mail scanned
Reviewed and tunedYes
On, never reviewedOften not
Built-in protection onlyDepends on preset
Teams links checked
Reviewed and tunedYes
On, never reviewedSometimes
Built-in protection onlyYes
Office document links checked
Reviewed and tunedYes
On, never reviewedSometimes
Built-in protection onlyYes
Rewriting decision made deliberately
Reviewed and tunedYes
On, never reviewedNo
Built-in protection onlyNot applicable
Click-through to malicious sites blocked
Reviewed and tunedYes
On, never reviewedOften allowed
Built-in protection onlyPer preset
Do not rewrite list reviewed
Reviewed and tunedYes
On, never reviewedNo
Built-in protection onlyNot applicable
Policy priority understood
Reviewed and tunedYes
On, never reviewedNo
Built-in protection onlyNot applicable
Click telemetry used in hunting
Reviewed and tunedYes
On, never reviewedNo
Built-in protection onlyNo
Coverage gaps known and accepted
Reviewed and tunedYes
On, never reviewedNo
Built-in protection onlyNo
Feature
Reviewed and tuned
On, never reviewed
Built-in protection only
Inbound email links checked at click
YesUsuallyYes
Internal mail scanned
YesOften notDepends on preset
Teams links checked
YesSometimesYes
Office document links checked
YesSometimesYes
Rewriting decision made deliberately
YesNoNot applicable
Click-through to malicious sites blocked
YesOften allowedPer preset
Do not rewrite list reviewed
YesNoNot applicable
Policy priority understood
YesNoNot applicable
Click telemetry used in hunting
YesNoNo
Coverage gaps known and accepted
YesNoNo
The coverage map

Where Safe Links applies, and the condition attached to each.

Coverage and exclusions as published. The right hand column is the practical consequence in a real estate, which is ours.
Surface or caseCoveredCondition or consequence
Inbound emailYesScanned at delivery and, if rewriting is on, again at click
Internal to internal emailOnly if configuredRequires the apply within the organization setting, recommended on
Microsoft TeamsYes, separatelyNot rewritten, checked at click, up to 24 hours to take effect
Office appsYes, separatelyDocuments rather than email, needs modern auth and a work account
Manual forwards and repliesYesURLs are rewritten again, per recipient, including newly added links
Automatic forwarding and SMTP forwardingConditionalNot rewritten for the final recipient unless they are also protected or the URL was already rewritten
Mail-enabled public foldersNoStated explicitly as not working
Rich text format and TNEF messagesNoNo protection for URLs in this format
S and MIME signed messagesNoIgnored by Safe Links
Link types other than HTTP, HTTPS and FTPNoOnly those three formats are supported
SharePoint and OneDrive URLsYes, without wrappingNo longer wrapped but still processed, which improves load performance
Links already wrapped by another productPossibly notAnother wrapping service before Defender might prevent processing entirely
How a review runs

Five steps, and most of it is done in a day.

A Safe Links review is short because the feature is already licensed and already on. The work is establishing what the current configuration actually does, then deciding what it should do.
  1. 1

    Inventory the policies and their priority

    Every Safe Links policy, its recipient filters, and its priority order, remembering that processing stops at the first match, that Standard and Strict presets always apply before custom policies, and that Built-in protection applies last. This produces the real answer to which policy applies to which person.

  2. 2

    Check the three surfaces separately

    Email, Teams and Office apps are three distinct settings and are frequently in three different states. We check each, including whether messages between internal senders and recipients are scanned, which is the setting most often found off despite being recommended on.

  3. 3

    Decide the rewriting question deliberately

    Rewriting on, or API-only checking. We put the published failure scenario in front of the decision maker rather than arguing from preference, and where the driver is user complaints about URL appearance, we propose a maintained do not rewrite list as the alternative to losing click-time protection.

  4. 4

    Rebuild the do not rewrite list correctly

    Reviewing existing entries against the documented wildcard behaviour, where a subdomain wildcard does not cover the bare domain and up to three wildcards are permitted per entry. Also noting that Teams and Office web apps do not recognise these lists, so an entry there is not a universal allow.

  5. 5

    Turn on the telemetry and use it

    Track user clicks enabled, organisation branding applied to warning pages so users can distinguish a genuine warning from an attacker imitation, and click events used in advanced hunting where Safe Links wrapped URLs appear with a mail application value in the click events table. Configuration without telemetry is a control nobody learns from.

Straight answers

What organisations ask about Safe Links.

Partly. Microsoft states there is no default Safe Links policy, but the Built-in protection preset security policy provides Safe Links protection in email, Teams and files in supported Office apps to all recipients for customers with at least one Defender for Office 365 licence. It applies to users not defined in the Standard or Strict presets or in custom policies, and it is always applied last in the priority order.

We would advise against it, and the argument is Microsoft own. The published scenario describes an organisation that disabled rewriting in favour of API-only checking. A user clicked a link in an alternative email client that does not support the Safe Links API. The link was legitimate on delivery and weaponised later. The published outcome is that the user is phished. API-only checking works in supported Outlook versions on Windows, Mac and the web, and nowhere else.

Only if you turn that on. The Apply Safe Links to email messages sent within the organization setting controls scanning of messages between internal senders and internal recipients in the same Exchange Online organisation, and Microsoft recommended value is on. It is the single most common gap we find, and it is also the gap that matters most, because lateral phishing from a compromised internal mailbox is the more credible attack.

It is a separate setting, and URLs are not rewritten. Links are checked at time of click against a list of known malicious links, across Teams desktop, web and Android and iOS mobile apps. Two operational details matter: changing the setting can take up to 24 hours to take effect, and if the person who sent the link is not covered by a Teams-enabled policy, they remain free to click through to the original URL themselves.

Links in Office documents, not links in email messages, though it can check links inside an attached Office document once that document is opened. It requires current versions of the supported apps, modern authentication, and users signed in with work or school accounts. Microsoft also notes it may take several seconds at the start of each session to verify that protection is available to the user.

Microsoft lists the exclusions. Safe Links does not work on mail-enabled public folders. It supports only HTTP, HTTPS and FTP link formats. It provides no protection for URLs in rich text format messages, also known as Transport Neutral Encapsulation Format. It ignores messages signed with S and MIME. Knowing these is not a criticism of the product, it is what lets you decide whether another control is needed for those paths.

If rewriting is enabled, URLs are rewritten even when a message is manually forwarded or replied to, per recipient, and any links added to the forwarded message are also rewritten. Automatic forwarding is different: for Inbox rules or SMTP forwarding, the URL is not rewritten in the message intended for the final recipient unless that recipient is also protected by Safe Links, or the URL was already rewritten in a previous communication.

Yes, in a documented case. Microsoft states that if a system failure occurs when reading the Safe Links policy configuration from certain apps, giving classic Outlook as the example, the user does not receive Safe Links protection and is redirected to the clicked link. In Office apps, if scanning cannot complete, protection does not trigger, though in Office desktop clients the user is warned before proceeding.

Priority. Microsoft states no two policies can have the same priority, processing stops after the first policy is applied, Standard and Strict preset policies are always applied before custom Safe Links policies, and Built-in protection is always applied last. If the recipients of your new custom policy are already covered by a preset, the preset wins and your policy never applies to them.

Entries are not scanned or wrapped during mail flow, but Microsoft warns they might still be blocked at time of click, and points to reporting the URL as clean and adding an allow entry in the Tenant Allow Block List for a stronger exclusion. Two further caveats: Teams and Office web apps do not recognise these lists at all, and only one list applies per user, from whichever single policy wins on priority.

Up to three wildcards per URL entry. Microsoft states that an entry for contoso.com allows the domain but not subdomains or paths, that a subdomain wildcard entry does not cover the bare domain so both are needed, and that an entry for a path with a wildcard covers subpaths while one without does not. Its recommended form for a domain plus all subdomains and paths uses two entries rather than one broad pattern.

Microsoft recommended value for Let users click through to the original URL is not selected, meaning users cannot proceed to a URL detected as malicious. We agree, and in Teams the setting is even more consequential because a link clicked from a pinned tab shows the warning inside Teams with the option to open it in a browser disabled for security reasons.

Microsoft documents five. Scan in progress means the URL is still being checked. Suspicious message means the URL was in a message similar to other suspicious messages. Phishing attempt means the message was identified as phishing, so all URLs in it are blocked. Malicious website means the destination itself is known bad. Error means the URL could not be opened. Applying your own branding to these pages helps users distinguish a real warning from an attacker imitation.

Yes, if Track user clicks is enabled, which Microsoft recommends. Click data is stored for URLs clicked, and in advanced hunting, click events on URLs wrapped by Safe Links appear in the URL click events table with a mail application value. That telemetry is genuinely useful during an incident, and it is frequently switched on and never queried.

A Safe Links configuration review is small enough that we normally fold it into a wider Defender for Office 365 assessment rather than pricing it alone. The feature is already licensed in most tenants we look at, so the output is a set of configuration changes rather than a purchase, and the two or three findings we consistently make are usually worth more than the effort involved.
Configuration review

Fifteen settings worth checking on an existing tenant.

Most organisations we look at have Safe Links on and have never reviewed it. These are the checks that most often find something.

Coverage

  • Is internal to internal mail scanned?
    Recommended on, frequently off.
  • Is Teams protection enabled?
    A separate setting in the policy.
  • Is Office apps protection enabled?
    Also separate, and it covers documents.
  • Who is left on Built-in protection only?
    It applies last, to everyone not covered.
  • Is another product wrapping links first?
    That can stop Safe Links processing them.

Behaviour

  • Is URL rewriting on or API-only?
    The documented phishing case is in API-only.
  • Is real-time scanning of file links on?
    Recommended on.
  • Do you wait for scanning before delivery?
    Recommended on, adds slight latency.
  • Can users click through a warning?
    Microsoft recommends this stays off.
  • Is click tracking enabled?
    Recommended on, and it feeds advanced hunting.

Policy hygiene

  • Do policy priorities make sense?
    First match wins, then processing stops.
  • Has the do not rewrite list been reviewed?
    Only one list applies per user.
  • Are wildcard entries correct?
    A domain and its subdomains need two entries.
  • Is organisation branding on warning pages?
    Users recognise a branded warning.
  • Does anyone look at click data?
    Otherwise the telemetry is wasted.
Related reading

The pages around this one.

Defender for Office 365

The product Safe Links belongs to, and the rest of what it does.

Learn more

Phishing protection

The vendor-neutral view, including the human layer Safe Links cannot cover.

Learn more

Attack simulation training

Testing whether your people click, and what happens when they do.

Learn more
Next step

Ask whether your internal mail is being scanned. Most tenants we check are not.

It is one setting, Microsoft recommends it on, and it covers the attack most UAE organisations are actually exposed to. Checking it takes minutes and it is rarely the only thing a review finds.

Book a Safe Links configuration reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Email Security Audit

Authentication, policy, exceptions, routing, mailboxes

Learn more

Defender for Office 365

Plan 1 versus Plan 2, and the ten second way to tell which you have

Learn more

Phishing Protection

Defender for Office 365, DMARC, simulation campaigns

Learn more

Attack Simulation Training

Phishing simulation you probably already own, including QR codes

Learn more

Email Encryption

Works to Gmail, and the three conditions revocation actually needs

Learn more

Defender XDR

Eleven signal sources, one incident, and containment without a human

Learn more

Security Awareness Training

Phishing simulation and behavior-change training

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy