What you need to know
Why can a directly created URL allow entry fail to override malware or high-confidence phishing?
Potentially affected
Microsoft 365 cloud-mailbox URL exceptions in the Tenant Allow/Block List.
DSE recommendation
Classify the actual filtering verdict before choosing the supported URL false-positive submission route.
Source facts
Direct URL allow entries in the Tenant Allow/Block List override bulk, spam, high-confidence spam and ordinary phishing verdicts only. Overriding malware or high-confidence phishing requires the URL submission route with its allow option. An allow entry does not stop Safe Links from wrapping the URL. Separately, at time of click, a URL allow entry overrides all filters associated with that URL entity. Microsoft directs non-Microsoft phishing-simulation URLs to advanced delivery, not this list. Microsoft Learn.
Applicability
This decision concerns a suspected URL false positive in a cloud-mailbox environment. Keep mail-flow verdict overrides distinct from the documented time-of-click behavior; this is not the workflow for a planned phishing simulation.
DSE recommendation
Classify the actual filtering verdict before choosing the supported URL false-positive submission route. Have an authorized reviewer establish why the destination is believed clean and retain the relevant message and URL evidence. Do not respond to an ineffective direct entry by creating progressively broader exceptions. Keep the investigation of the verdict distinct from any request to change URL rewriting behavior.
Verification
Review the entry’s Override verdicts value and whether its details link to a submission. Compare the approved URL with the actual filtered entity and examine appropriate mail-flow evidence for the intended verdict override. Evaluate time-of-click behavior separately rather than using an allowed click to prove the entry’s mail-flow verdict coverage. Retain the decision and a removal or reassessment date; no exception or live click is claimed to have been performed here.
Official references
Microsoft Learn: Tenant Allow/Block List URLs. Source reviewed September 9, 2026.
Review the official source
Allow or block URLs using the Tenant Allow/Block List - Microsoft Defender for Office 365 | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE