Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A company uses Microsoft Defender for Office 365. Users report receiving phishing emails that contain malicious URLs, even though Safe Links is enabled. Upon investigation, the administrator discovers that the URLs are within attachments (e.g., PDF documents) and are not being rewritten by Safe Links. What is the most likely reason for this behavior?

  1. AThe emails are bypassing the Defender for Office 365 protection due to a mail flow rule.
  2. BSafe Links scanning of URLs in attachments is not enabled in the policy.
  3. CSafe Links policies are not applied to internal recipients.
  4. DThe Safe Links policy is configured to 'Do not rewrite URLs in emails'.
Show answer & explanation

Correct answer: B. Safe Links scanning of URLs in attachments is not enabled in the policy.

Safe Links provides an option to scan URLs within email messages AND within attachments. If the policy is not specifically configured to scan URLs in attachments, then URLs embedded in documents like PDFs will not be rewritten or checked by Safe Links. Option B refers to email body URLs, not attachments. Option A is incorrect as Safe Links applies to internal recipients. Option D is a possibility but less likely the 'most likely' reason given the specific detail of URLs in attachments not being rewritten while Safe Links is generally 'enabled'.

Why the other options are wrong

  • A. While possible, a mail flow rule bypassing protection would likely affect all aspects of message scanning, not just URLs in attachments while Safe Links is otherwise active.
  • C. Safe Links policies can and often do apply to internal recipients for comprehensive protection.
  • D. This setting would prevent URL rewriting in the email body, but the issue is specifically about URLs *within attachments*.

Safe Links for Attachments

Microsoft Defender for Office 365 Safe Links can be configured to scan and rewrite URLs found within email attachments, providing an additional layer of protection against phishing and malware.

  • Requires explicit enablement in Safe Links policy.
  • Protects against malicious URLs in documents like PDFs, Word, Excel.
  • Separate setting from scanning URLs in email body.

Memory trick: Remember, 'Safe Links' needs to 'Scan' 'Attachments' 'Explicitly' to catch hidden threats.

More Implement and manage Microsoft Defender XDR questions