How to Stop Safe Links URL Detonation in Phishing Simulations
Question details
The user wants to know how to prevent Microsoft Defender's URL detonation from prematurely activating phishing simulation links.

- Product
- Microsoft Defender
- Device & OS
- not provided
- Scenario
- Running internal phishing simulation campaigns without interference from automated security scanning tools.
- Observed behavior
- Safe Links URL detonation in Microsoft Defender automatically activates phishing simulation links, creating false positives in simulation results.
Ensure you have administrator access to the Microsoft 365 Defender portal and obtain the specific domains, IPs, and simulation URLs from your phishing simulation provider (e.g., KnowBe4).
Configure Advanced Delivery Policy and Bypass Settings
Set up exclusions and advanced delivery policies in Microsoft Defender to allow phishing simulation URLs to bypass Safe Links detonation.
Standard Safe Links exclusions are often not enough to prevent URL detonation during phishing simulations. You must explicitly configure an Advanced Delivery Policy alongside Safe Links and Safe Attachments bypass settings to ensure accurate simulation results.
Sign in to the Microsoft 365 Defender portal using your administrator credentials.
Go to Email & collaboration > Policies & rules > Threat policies > Advanced delivery.
Under the Phishing Simulation tab, add your provider's specific sending IP addresses, sending domains, and simulation URLs.
Adjust Safe Links and Safe Attachments bypass settings, SmartScreen allowlists, and Defender for Endpoint indicators for the approved domains to completely exclude them from automated detonation.

Contact Microsoft Defender In-App Support
Use the built-in Microsoft Defender support tool if policy configurations do not resolve the URL detonation issue.
Experience a Secure and Lightweight Office Suite with WPS Office
While managing security policies and IT administration, you need a dependable office suite for your daily reports and documentation. WPS Office is a highly compatible, fast, and free alternative to Microsoft Office that supports secure document management without the heavy overhead.

Frequently Asked Questions
Why do phishing simulation links get clicked automatically?
Security tools like Microsoft Defender use a feature called URL detonation (or Safe Links) to scan and test links in incoming emails. This automated scanning accesses the link in a sandbox environment, which registers as a 'click' on the phishing simulation platform, causing false positives.
Do standard Safe Links exclusions prevent URL detonation?
Standard exclusions are typically insufficient for specialized testing. You need to configure an Advanced Delivery Policy specifically designed for phishing simulations to properly bypass Safe Links and Safe Attachments detonation.
What information do I need from my phishing simulation provider?
You will need the exact sending IP addresses, sending domains, and specific simulation URLs used by your provider (such as KnowBe4) to accurately configure the allowlists and bypass settings in Microsoft Defender.




