Configure the Microsoft Defender Safe Links policies to allow browsing to SMARTFENSE domains without being blocked as malicious sites. This configuration is the solution when, during a phishing simulation, users receive the email correctly but see a Microsoft Defender block message when clicking the link.
Note: this article covers exclusions at the navigation URL level within the Microsoft Defender portal. It complements the Header configuration applied to simulation emails. For Safe Links bypass by Header on incoming emails, see the article Microsoft - Implementing Whitelist in ATP when using DMI sending method.
When Do You Need This Configuration?
Apply this configuration when both of the following conditions occur during a phishing simulation:
- The simulation email arrives correctly in the user’s inbox.
- Clicking the simulation link results in a Microsoft Defender warning blocking access to the site.
The typical warning message is as follows:
This website is classified as malicious.
Opening this website might not be safe.
We recommend that you do not open this website. It may be unsafe, harm your device, or lead to malicious use of your personal data.
This message corresponds to real-time analysis by Safe Links: Microsoft Defender detects the simulation URL as suspicious and blocks user navigation. As a result, campaign statistics do not record clicks or subsequent interactions, diminishing the simulation’s educational value.
With the configuration described in this article, URLs from SMARTFENSE domains are excluded from Safe Links analysis, user navigation is no longer intercepted, and campaign statistics resume normal recording.
Prerequisites
Before starting the configuration, ensure you meet the following:
- Have an administrator role in Microsoft Defender. Common roles include Security Administrator or Global Administrator.
- Access to the SMARTFENSE platform to consult the list of navigation domains under Settings > Security > Whitelist.
- Know the name of the active Safe Links policy in your tenant.
Configuration Steps
1. Access the Microsoft Defender Portal
Go to https://security.microsoft.com and sign in with an account that has an administrator role.
2. Navigate to Safe Links Policies
Navigate to Email & collaboration > Policies & rules > Threat policies > Safe Links.
3. Edit the Existing Policy
Click on the active policy to open it in edit mode.
Important: if your organization has multiple Safe Links policies applied to different groups, repeat steps 3 and 4 for each to ensure full coverage.
4. Add SMARTFENSE URLs to the Exclusion List
In the Do not rewrite the following URLs section, add the SMARTFENSE navigation domains. Click Save.
Where can I find the exact domains? The SMARTFENSE navigation domains are available in the Settings > Security > Whitelist section of the platform. They are also listed in the article Whitelist Process in SMARTFENSE.
5. Reinforce with Tenant-Level Allow List
As an additional measure, go to Threat policies > Tenant allow/block lists > URLs and add the same SMARTFENSE domains to the Allowed list.
This step ensures the domains remain enabled even when the Safe Links policy does not apply to the mailbox (for example, in specific licenses or legacy configurations).
Verify the Configuration
After saving the configuration, verify that the domains are effectively excluded:
- Wait up to two hours for the policies to propagate to all tenant users.
- Send a test simulation to a mailbox within the policy’s scope.
- Confirm in the delivered email that links to SMARTFENSE domains are not rewritten with the prefix
safelinks.protection.outlook.com. - Check in the SMARTFENSE platform that campaign statistics do not show immediate automatic clicks after sending.
Note: if statistics still show false clicks or the link continues to be rewritten, verify that the domains were added exactly as they appear in the SMARTFENSE Whitelist section, without extra spaces or invisible characters.
💡 Best Practices
- Consult and apply the full list of navigation domains from Settings > Security > Whitelist in SMARTFENSE. Domains may vary by instance and update with new platform versions.
- Apply the same list in both the Safe Links policy and the tenant allow list to cover mixed-license scenarios.
- If you have multiple active Safe Links policies, ensure all include the SMARTFENSE domains.
- Internally document the date and responsible party for the last update of the exclusion list to facilitate audits and renewals.
- After any major changes to Microsoft Defender policies, validate with a test campaign that the exclusion configuration remains effective.
- Combine this configuration with Safe Links bypass by Header when using DMI to cover both link rewriting in email and subsequent navigation interception.