top of page

Microsoft Defender - Safe Links

Writer: Bjørnar AassveenBjørnar Aassveen

🥷Upcoming changes to M365 Copilot Chat include integration with SafeLinks for URL protection. The rollout will begin in late March 2025 and will be complete by late May 2025. These updates improve link security in chat replies.🥷



  1. Integration with SafeLinks: M365 Copilot Chat will integrate with SafeLinks in Defender for Office 365 to provide URL protection with click time for the hyperlinks included in chat responses.

    1. This change applies to users with Microsoft Defender for Office 365 Plan 1 or Plan 2. No policy change is required in the SafeLinks policy.

  2. Built-in time of click URL reputation check:

    1. For users without SafeLinks protection (which is available as part of Microsoft Defender for Office 365), M365 Copilot Chat will natively enable URL reputation checking for click time for the hyperlinks returned in chat responses.



What are Safe Links?

Safe Links are security features in Microsoft Defender for Office 365 that protect your organization from malicious links in emails, Microsoft Teams, and Office 365 apps. These features provide an additional layer of protection beyond standard anti-spam and anti-malware protection.


  • Safe Links scans and rewrites URLs in incoming emails during email flow, and performs URL verification at the time of click⭐. This protects users from phishing attacks and other threats


Licensing

Safe Links and Safe Attachments are available in both Microsoft Defender for Office 365 Plan 1 and Plan 2. It is important to note that the features are available to all recipients who have at least one Defender for Office 365 license. (**). Not sure what is included in your license? Check out m365maps.com, an example of an E3 and E5 comparison below

(**)



Configuring Safe Links

Go to security.microsoft.com --> Email & collaboration -> Policies & Rules


The example below shows the options you have under Safe Links, after you have selected which users or groups you want to scope policy to. Here, a separate option will most likely appear for Copilot Chat, if it is not baked into "Office 365 apps".



Another clever feature that came in late fall 2024 is that Safe Links now no longer needs to rewrite URLs. You may have previously seen that links in emails have become long and in the format: https://<DataCenterLocation>.safelinks.protection.outlook.com. You can now opt-out of this by checking "Do not rewrite URLs, do checks via Safe Links API only."


The purpose of "Track user clicks" in the Microsoft Safe Links policy is to store data about which URLs users click on. This gives you better insight into user behavior and helps you identify and investigate potential threats.


Bjørnar&AI


Recent Posts

See All

Comments


bottom of page