{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
        "slug": "dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/"
        },
        "title": "Use the submission route when a URL exception must address a high-confidence verdict",
        "summary": "Why can a directly created URL allow entry fail to override malware or high-confidence phishing?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:29+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 257,
        "potentially_affected": "Microsoft 365 cloud-mailbox URL exceptions in the Tenant Allow/Block List.",
        "dse_recommendation": "Classify the actual filtering verdict before choosing the supported URL false-positive submission route.",
        "primary_source": {
            "name": "Allow or block URLs using the Tenant Allow/Block List - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Direct URL allow entries in the Tenant Allow/Block List override bulk, spam, high-confidence spam and ordinary phishing verdicts only. Overriding malware or high-confidence phishing requires the URL submission route with its allow option. An allow entry does not stop Safe Links from wrapping the URL. Separately, at time of click, a URL allow entry overrides all filters associated with that URL entity. Microsoft directs non-Microsoft phishing-simulation URLs to advanced delivery, not this list. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This decision concerns a suspected URL false positive in a cloud-mailbox environment. Keep mail-flow verdict overrides distinct from the documented time-of-click behavior; this is not the workflow for a planned phishing simulation.</p>\n<h2>DSE recommendation</h2>\n<p>Classify the actual filtering verdict before choosing the supported URL false-positive submission route. Have an authorized reviewer establish why the destination is believed clean and retain the relevant message and URL evidence. Do not respond to an ineffective direct entry by creating progressively broader exceptions. Keep the investigation of the verdict distinct from any request to change URL rewriting behavior.</p>\n<h2>Verification</h2>\n<p>Review the entry&#8217;s Override verdicts value and whether its details link to a submission. Compare the approved URL with the actual filtered entity and examine appropriate mail-flow evidence for the intended verdict override. Evaluate time-of-click behavior separately rather than using an allowed click to prove the entry&#8217;s mail-flow verdict coverage. Retain the decision and a removal or reassessment date; no exception or live click is claimed to have been performed here.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Tenant Allow/Block List URLs</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDirect URL allow entries in the Tenant Allow/Block List override bulk, spam, high-confidence spam and ordinary phishing verdicts only. Overriding malware or high-confidence phishing requires the URL submission route with its allow option. An allow entry does not stop Safe Links from wrapping the URL. Separately, at time of click, a URL allow entry overrides all filters associated with that URL entity. Microsoft directs non-Microsoft phishing-simulation URLs to advanced delivery, not this list. Microsoft Learn.\nApplicability\nThis decision concerns a suspected URL false positive in a cloud-mailbox environment. Keep mail-flow verdict overrides distinct from the documented time-of-click behavior; this is not the workflow for a planned phishing simulation.\nDSE recommendation\nClassify the actual filtering verdict before choosing the supported URL false-positive submission route. Have an authorized reviewer establish why the destination is believed clean and retain the relevant message and URL evidence. Do not respond to an ineffective direct entry by creating progressively broader exceptions. Keep the investigation of the verdict distinct from any request to change URL rewriting behavior.\nVerification\nReview the entry’s Override verdicts value and whether its details link to a submission. Compare the approved URL with the actual filtered entity and examine appropriate mail-flow evidence for the intended verdict override. Evaluate time-of-click behavior separately rather than using an allowed click to prove the entry’s mail-flow verdict coverage. Retain the decision and a removal or reassessment date; no exception or live click is claimed to have been performed here.\nOfficial references\nMicrosoft Learn: Tenant Allow/Block List URLs. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDirect URL allow entries in the Tenant Allow/Block List override bulk, spam, high-confidence spam and ordinary phishing verdicts only. Overriding malware or high-confidence phishing requires the URL submission route with its allow option. An allow entry does not stop Safe Links from wrapping the URL. Separately, at time of click, a URL allow entry overrides all filters associated with that URL entity. Microsoft directs non-Microsoft phishing-simulation URLs to advanced delivery, not this list. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure).\n\n## Applicability\n\nThis decision concerns a suspected URL false positive in a cloud-mailbox environment. Keep mail-flow verdict overrides distinct from the documented time-of-click behavior; this is not the workflow for a planned phishing simulation.\n\n## DSE recommendation\n\nClassify the actual filtering verdict before choosing the supported URL false-positive submission route. Have an authorized reviewer establish why the destination is believed clean and retain the relevant message and URL evidence. Do not respond to an ineffective direct entry by creating progressively broader exceptions. Keep the investigation of the verdict distinct from any request to change URL rewriting behavior.\n\n## Verification\n\nReview the entry’s Override verdicts value and whether its details link to a submission. Compare the approved URL with the actual filtered entity and examine appropriate mail-flow evidence for the intended verdict override. Evaluate time-of-click behavior separately rather than using an allowed click to prove the entry’s mail-flow verdict coverage. Retain the decision and a removal or reassessment date; no exception or live click is claimed to have been performed here.\n\n## Official references\n\n[Microsoft Learn: Tenant Allow/Block List URLs](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Use the submission route when a URL exception must address a high-confidence verdict",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/",
                "headline": "Use the submission route when a URL exception must address a high-confidence verdict",
                "description": "Why can a directly created URL allow entry fail to override malware or high-confidence phishing?",
                "abstract": "Why can a directly created URL allow entry fail to override malware or high-confidence phishing?",
                "articleBody": "Source facts\nDirect URL allow entries in the Tenant Allow/Block List override bulk, spam, high-confidence spam and ordinary phishing verdicts only. Overriding malware or high-confidence phishing requires the URL submission route with its allow option. An allow entry does not stop Safe Links from wrapping the URL. Separately, at time of click, a URL allow entry overrides all filters associated with that URL entity. Microsoft directs non-Microsoft phishing-simulation URLs to advanced delivery, not this list. Microsoft Learn.\nApplicability\nThis decision concerns a suspected URL false positive in a cloud-mailbox environment. Keep mail-flow verdict overrides distinct from the documented time-of-click behavior; this is not the workflow for a planned phishing simulation.\nDSE recommendation\nClassify the actual filtering verdict before choosing the supported URL false-positive submission route. Have an authorized reviewer establish why the destination is believed clean and retain the relevant message and URL evidence. Do not respond to an ineffective direct entry by creating progressively broader exceptions. Keep the investigation of the verdict distinct from any request to change URL rewriting behavior.\nVerification\nReview the entry’s Override verdicts value and whether its details link to a submission. Compare the approved URL with the actual filtered entity and examine appropriate mail-flow evidence for the intended verdict override. Evaluate time-of-click behavior separately rather than using an allowed click to prove the entry’s mail-flow verdict coverage. Retain the decision and a removal or reassessment date; no exception or live click is claimed to have been performed here.\nOfficial references\nMicrosoft Learn: Tenant Allow/Block List URLs. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:29:29+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-147-use-the-submission-route-when-a-url-exception-must-address-a-high-confidence/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Use the submission route when a URL exception must address a high-confidence verdict"
                },
                "articleSection": [
                    "Cybersecurity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 257,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Allow or block URLs using the Tenant Allow/Block List - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-urls-configure"
                }
            }
        ]
    }
}