Your organization uses Microsoft Defender for Office 365 and wants to block malicious links in email messages in real time. Which policy should you configure?
The Safe Links policy is the correct control because it directly handles malicious URLs by rewriting every link in email at the time of delivery and then performing a verdict check at the moment of click using Microsoft's threat intelligence. This time-of-click protection means that even if a URL was previously benign, it can be re-evaluated and blocked as soon as the user clicks. Safe Links extends beyond email to Teams, Office documents, and other supported workloads, making it the dedicated mechanism for URL-based threats.
Why this answer
Safe Links policy in Microsoft Defender for Office 365 provides real-time URL scanning and rewriting at the time of click, enabling the blocking of malicious links in email messages. This policy wraps URLs to route clicks through Microsoft's threat intelligence service, which checks the link against current threat data and blocks access if malicious content is detected.
Exam trap
The trap here is that candidates often confuse Safe Links with Safe Attachments, mistakenly thinking that attachment scanning covers embedded links, but Safe Attachments only handles file payloads, not URLs.
How to eliminate wrong answers
Option A is wrong because Anti-phishing policy is designed to protect against impersonation attacks and phishing attempts by analyzing sender identity and message content, not by scanning or blocking individual URLs in real time. Option B is wrong because Safe Attachments policy focuses on scanning email attachments for malware using detonation in a sandbox environment, not on inspecting links within the message body. Option D is wrong because Anti-spam policy filters messages based on bulk mail, spam, and spoofing criteria, and does not perform real-time URL blocking or rewriting.