Turning off URL rewriting looks tidy. Microsoft own documentation shows the user who gets phished because of it.
Safe Links scans and rewrites URLs in inbound mail during mail flow, then verifies them again at time of click in email, Teams and supported Office apps. The configuration choices matter more than the switch: there is no default policy, several message types are not covered at all, and the API-only mode has a documented failure case.

- Time of clickNot just at delivery
- Mail, Teams, OfficeThree separate policy settings
- No default policyBuilt-in protection preset covers the gap
- Priority orderedFirst matching policy wins, then stops
Eight things that decide whether Safe Links is actually protecting your people.
Time-of-click verification, which is the whole point
A link is checked when the user clicks it, not only when the message arrived. Attackers know this, which is why campaigns increasingly deliver a clean URL and weaponise the destination hours later. Microsoft states that as long as Safe Links protection is on, URLs are scanned prior to delivery regardless of whether they are rewritten, and if rewriting is enabled they are scanned again on click.
There is no default policy, but there is built-in protection
Microsoft states plainly that although there is no default Safe Links policy, the Built-in protection preset security policy provides Safe Links protection in email, Teams and files in supported Office apps to all recipients for customers with at least one Defender for Office 365 licence. So doing nothing is not the same as having nothing, but it is also not the same as having a deliberate configuration.
Rewriting versus API-only, and the documented consequence
The Do not rewrite URLs setting checks via the Safe Links API instead of wrapping. Microsoft publishes the failure case: a user clicks a link in an alternative email client that does not support the API, the link was legitimate on delivery and weaponised later, and the published result is that the user is phished, because the link was not malicious on delivery. Tidy URLs, real exposure.
Teams is a separate setting, and it does not rewrite
Teams protection is enabled separately in the policy and covers desktop, web, and Android and iOS mobile apps. URLs are not rewritten, they are checked at time of click against a list of known malicious links. Two operational details: enabling or disabling can take up to 24 hours to take effect, and if the sender is not covered by a Teams-enabled policy they can still click through to the original URL themselves.
Office apps protection checks documents, not email
Microsoft is precise: Safe Links protection for Office apps checks links in Office documents, not links in email messages, though it can check links in attached Office documents once the document is opened. It requires supported apps configured for modern authentication and users signed in with work or school accounts, and Microsoft notes it may take several seconds at the start of each session to verify availability.
Internal mail is not covered unless you say so
The Apply Safe Links to email messages sent within the organization setting controls whether messages between internal senders and internal recipients in the same Exchange Online organisation are scanned. Microsoft recommended value is on. Since compromised internal mailboxes are how most lateral phishing works in the UAE market, leaving this off removes protection from the most credible attack.
Policy priority, and processing stops at the first match
Microsoft states no two policies can have the same priority, and processing stops after the first policy is applied, meaning the highest priority policy for that recipient. Standard and Strict preset policies are always applied before custom policies, and Built-in protection is always applied last. A user in several policies gets exactly one, including exactly one do-not-rewrite list.
Several message types are simply not covered
Microsoft lists them: Safe Links does not work on mail-enabled public folders, supports only HTTP, HTTPS and FTP link formats, does not protect URLs in rich text format messages also known as TNEF, and ignores S and MIME signed messages. It also notes that using another service to wrap links before Defender for Office 365 might prevent Safe Links from processing them at all.
Users hate wrapped URLs. Microsoft published what happens when you stop wrapping them.
The request to turn off URL rewriting almost always comes from the business, and the counter-argument is in Microsoft own scenario table rather than in our opinion.
- The published scenario, quoted: an IT department configured Safe Links not to rewrite URLs and to check via API only. The user clicks a link in an alternative email client that does not support the Safe Links API. The link was legitimate on delivery but was later weaponised.
- The published outcome, quoted: the user is phished, because the link was not malicious on delivery, so Safe Links did not detect it. The API call that would have caught it at click never happened, because that client does not support it.
- API-only checking works in supported versions of Outlook on Windows, Mac and Outlook on the web. It does not help in clients outside that set, which in most organisations includes at least one team using something else.
- There is a middle path worth knowing about: rewriting is still enabled, and a well-maintained do not rewrite list covers the internal URLs users complain about most. That preserves click-time protection where it matters while removing the cosmetic irritation.
Four things a Safe Links review nearly always finds.
Internal mail is not being scanned
The setting to apply Safe Links to messages sent within the organisation is separate and frequently left off, even though Microsoft recommends it on. Given that lateral phishing from a compromised internal mailbox is the most credible attack most UAE organisations face, this is the highest-value single change in most reviews.
Users can click through the warning page
The Let users click through to the original URL setting controls whether a user can proceed past a malicious website warning. Microsoft recommended value is not selected, meaning users cannot proceed. In practice it is often on, which turns a block into a speed bump for exactly the people most likely to ignore it.
The policy priority order does not do what people think
Processing stops at the first matching policy, Standard and Strict presets always come before custom policies, and Built-in protection is always last. That means a carefully written custom policy can never apply to someone already covered by a preset, and only one do not rewrite list ever takes effect per user. Both surprise people regularly.
The do not rewrite list has wildcards that do not do what was intended
Microsoft is explicit that an entry for a subdomain wildcard does not cover the bare domain, so covering both needs two entries, and that up to three wildcards are allowed per entry. Lists written years ago routinely contain entries that exclude nothing, or exclude far more than anybody intended, and nobody has re-read them since.
Six UAE situations where the Safe Links configuration is worth an hour.
A financial firm targeted by payment redirection fraud
Business email compromise in the UAE frequently runs through a compromised supplier or internal mailbox rather than an obvious external sender. Scanning internal to internal mail, keeping click-through off, and enabling real-time scanning of links that point to files together address the delivery mechanism that these campaigns actually use.
A group that recently consolidated tenants
Consolidation leaves layered policies with overlapping recipient filters and priorities nobody set deliberately. Because processing stops at the first matching policy, half the estate can be running on a policy nobody remembers writing. Rationalising priority order is usually the fastest way to make coverage match intent.
An organisation running a third-party email security gateway
Microsoft notes that using another service to wrap links before Defender for Office 365 might prevent Safe Links from processing them, including wrapping, detonating or otherwise validating the link. Where two products both rewrite, one of them is doing nothing, and knowing which is a fifteen minute check with real consequences.
A business that has moved most communication into Teams
Teams protection is a separate setting, does not rewrite URLs, and takes up to 24 hours to take effect when changed. There is also the sender caveat: if the person who sent the link is not covered by a Teams-enabled policy, they can still click through to the original URL themselves, which matters for shared and external-facing teams.
An operator whose users complain about wrapped links
The request to disable rewriting is almost always driven by the appearance of the wrapped URL rather than by any functional problem. A maintained do not rewrite list covering internal services such as intranet and line of business URLs solves the complaint without moving to API-only checking and its documented failure case.
A school or university with a diverse mail client estate
API-only checking works in supported Outlook versions on Windows, Mac and the web. Education estates in particular carry a long tail of other clients, which is exactly the population the published failure scenario describes. Where client diversity is high, rewriting is the safer default rather than the inconvenient one.
How UAE organisations configure link protection.
| Feature | Reviewed and tuned | On, never reviewed | Built-in protection only |
|---|---|---|---|
Inbound email links checked at click | Yes | Usually | Yes |
Internal mail scanned | Yes | Often not | Depends on preset |
Teams links checked | Yes | Sometimes | Yes |
Office document links checked | Yes | Sometimes | Yes |
Rewriting decision made deliberately | Yes | No | Not applicable |
Click-through to malicious sites blocked | Yes | Often allowed | Per preset |
Do not rewrite list reviewed | Yes | No | Not applicable |
Policy priority understood | Yes | No | Not applicable |
Click telemetry used in hunting | Yes | No | No |
Coverage gaps known and accepted | Yes | No | No |
Where Safe Links applies, and the condition attached to each.
| Surface or case | Covered | Condition or consequence | |
|---|---|---|---|
| Inbound email | Yes | Scanned at delivery and, if rewriting is on, again at click | |
| Internal to internal email | Only if configured | Requires the apply within the organization setting, recommended on | |
| Microsoft Teams | Yes, separately | Not rewritten, checked at click, up to 24 hours to take effect | |
| Office apps | Yes, separately | Documents rather than email, needs modern auth and a work account | |
| Manual forwards and replies | Yes | URLs are rewritten again, per recipient, including newly added links | |
| Automatic forwarding and SMTP forwarding | Conditional | Not rewritten for the final recipient unless they are also protected or the URL was already rewritten | |
| Mail-enabled public folders | No | Stated explicitly as not working | |
| Rich text format and TNEF messages | No | No protection for URLs in this format | |
| S and MIME signed messages | No | Ignored by Safe Links | |
| Link types other than HTTP, HTTPS and FTP | No | Only those three formats are supported | |
| SharePoint and OneDrive URLs | Yes, without wrapping | No longer wrapped but still processed, which improves load performance | |
| Links already wrapped by another product | Possibly not | Another wrapping service before Defender might prevent processing entirely |
Five steps, and most of it is done in a day.
- 1
Inventory the policies and their priority
Every Safe Links policy, its recipient filters, and its priority order, remembering that processing stops at the first match, that Standard and Strict presets always apply before custom policies, and that Built-in protection applies last. This produces the real answer to which policy applies to which person.
- 2
Check the three surfaces separately
Email, Teams and Office apps are three distinct settings and are frequently in three different states. We check each, including whether messages between internal senders and recipients are scanned, which is the setting most often found off despite being recommended on.
- 3
Decide the rewriting question deliberately
Rewriting on, or API-only checking. We put the published failure scenario in front of the decision maker rather than arguing from preference, and where the driver is user complaints about URL appearance, we propose a maintained do not rewrite list as the alternative to losing click-time protection.
- 4
Rebuild the do not rewrite list correctly
Reviewing existing entries against the documented wildcard behaviour, where a subdomain wildcard does not cover the bare domain and up to three wildcards are permitted per entry. Also noting that Teams and Office web apps do not recognise these lists, so an entry there is not a universal allow.
- 5
Turn on the telemetry and use it
Track user clicks enabled, organisation branding applied to warning pages so users can distinguish a genuine warning from an attacker imitation, and click events used in advanced hunting where Safe Links wrapped URLs appear with a mail application value in the click events table. Configuration without telemetry is a control nobody learns from.
What organisations ask about Safe Links.
Fifteen settings worth checking on an existing tenant.
Coverage
- Is internal to internal mail scanned?Recommended on, frequently off.
- Is Teams protection enabled?A separate setting in the policy.
- Is Office apps protection enabled?Also separate, and it covers documents.
- Who is left on Built-in protection only?It applies last, to everyone not covered.
- Is another product wrapping links first?That can stop Safe Links processing them.
Behaviour
- Is URL rewriting on or API-only?The documented phishing case is in API-only.
- Is real-time scanning of file links on?Recommended on.
- Do you wait for scanning before delivery?Recommended on, adds slight latency.
- Can users click through a warning?Microsoft recommends this stays off.
- Is click tracking enabled?Recommended on, and it feeds advanced hunting.
Policy hygiene
- Do policy priorities make sense?First match wins, then processing stops.
- Has the do not rewrite list been reviewed?Only one list applies per user.
- Are wildcard entries correct?A domain and its subdomains need two entries.
- Is organisation branding on warning pages?Users recognise a branded warning.
- Does anyone look at click data?Otherwise the telemetry is wasted.
The pages around this one.
Ask whether your internal mail is being scanned. Most tenants we check are not.
It is one setting, Microsoft recommends it on, and it covers the attack most UAE organisations are actually exposed to. Checking it takes minutes and it is rarely the only thing a review finds.
Related Services
Explore more solutions that work great with this service
Email Security Audit
Authentication, policy, exceptions, routing, mailboxes
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
Phishing Protection
Defender for Office 365, DMARC, simulation campaigns
Attack Simulation Training
Phishing simulation you probably already own, including QR codes
Email Encryption
Works to Gmail, and the three conditions revocation actually needs
Defender XDR
Eleven signal sources, one incident, and containment without a human
Security Awareness Training
Phishing simulation and behavior-change training
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own