logo
search
Security Policy Errors

How to Stop Safe Links URL Detonation in Phishing Simulations

Steve KSteve K Oct 7, 2026 869 views

Question details

The user wants to know how to prevent Microsoft Defender's URL detonation from prematurely activating phishing simulation links.

How to Stop Safe Links URL Detonation in Phishing Simulations
Product
Microsoft Defender
Device & OS
not provided
Scenario
Running internal phishing simulation campaigns without interference from automated security scanning tools.
Observed behavior
Safe Links URL detonation in Microsoft Defender automatically activates phishing simulation links, creating false positives in simulation results.
Before you start

Ensure you have administrator access to the Microsoft 365 Defender portal and obtain the specific domains, IPs, and simulation URLs from your phishing simulation provider (e.g., KnowBe4).

Solution 1Recommended

Configure Advanced Delivery Policy and Bypass Settings

Set up exclusions and advanced delivery policies in Microsoft Defender to allow phishing simulation URLs to bypass Safe Links detonation.

Standard Safe Links exclusions are often not enough to prevent URL detonation during phishing simulations. You must explicitly configure an Advanced Delivery Policy alongside Safe Links and Safe Attachments bypass settings to ensure accurate simulation results.

1
Access the Microsoft Defender Portal

Sign in to the Microsoft 365 Defender portal using your administrator credentials.

2
Navigate to Advanced Delivery

Go to Email & collaboration > Policies & rules > Threat policies > Advanced delivery.

3
Configure Phishing Simulation Overrides

Under the Phishing Simulation tab, add your provider's specific sending IP addresses, sending domains, and simulation URLs.

4
Update Additional Allow Lists

Adjust Safe Links and Safe Attachments bypass settings, SmartScreen allowlists, and Defender for Endpoint indicators for the approved domains to completely exclude them from automated detonation.

Configure Advanced Delivery Policy and Bypass Settings
Coordination Recommended: Work closely with your phishing simulation provider's support team to ensure all required URLs and IPs are correctly formatted and included in your policies.
Free Microsoft Office alternative

Experience a Secure and Lightweight Office Suite with WPS Office

While managing security policies and IT administration, you need a dependable office suite for your daily reports and documentation. WPS Office is a highly compatible, fast, and free alternative to Microsoft Office that supports secure document management without the heavy overhead.

Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight installation that runs smoothly on almost any device without triggering performance issues.Familiar and intuitive user interface for seamless migration from other office suites.Built-in PDF editing and secure document sharing features for robust enterprise usage.
microsoft office alternative - wps office

Frequently Asked Questions

Why do phishing simulation links get clicked automatically?

Security tools like Microsoft Defender use a feature called URL detonation (or Safe Links) to scan and test links in incoming emails. This automated scanning accesses the link in a sandbox environment, which registers as a 'click' on the phishing simulation platform, causing false positives.

Do standard Safe Links exclusions prevent URL detonation?

Standard exclusions are typically insufficient for specialized testing. You need to configure an Advanced Delivery Policy specifically designed for phishing simulations to properly bypass Safe Links and Safe Attachments detonation.

What information do I need from my phishing simulation provider?

You will need the exact sending IP addresses, sending domains, and specific simulation URLs used by your provider (such as KnowBe4) to accurately configure the allowlists and bypass settings in Microsoft Defender.