When you paste a link into a Teams chat with a guest, Teams may block it with a Safe Links warning even though the URL is safe. This happens because Microsoft Defender for Office 365 scans every link in Teams conversations, and guest users are treated with stricter policy settings. The warning appears as a red or yellow banner that says the link has been blocked or is potentially harmful. This article explains why the block occurs and shows you how to allow a legitimate URL for a guest conversation.
Key Takeaways: Unblocking a Safe Link Warning in Teams Guest Chats
- Teams admin center > Messaging policies > Safe links: Lets you turn off Safe Links scanning for your organization or for specific users.
- Microsoft 365 Defender portal > Policies & rules > Threat policies > Safe links: Contains the global Safe Links policy that you can edit to allow certain URLs.
- Safe Links URL block list: Lists domains and URLs that are always blocked, even if they are otherwise safe.
Why Teams Blocks a Valid URL in a Guest Conversation
Teams uses Microsoft Defender for Office 365 Safe Links to scan URLs in chats and channel messages. The scan happens in real time when a user sends a message. If the URL matches a block list or if the scan cannot verify the link as safe, Teams shows a warning and blocks the link from being clickable.
Guest users in Teams are treated as external entities. Their conversations are subject to the same Safe Links policies, but the scanning is often more aggressive because the guest’s tenant may not have the same security posture. Also, if your organization has a custom Safe Links policy that blocks certain domains or uses a strict URL reputation setting, a link that is safe for your internal users may be flagged for guests.
What the Safe Links Warning Looks Like
When a link is blocked, Teams displays a red banner in the chat window with a message like “This link has been blocked by your administrator” or “This URL is potentially harmful.” The link itself is not clickable, and the sender may not see the warning if the policy is applied only to the recipient’s side.
Steps to Allow a Safe URL That Is Blocked in a Guest Conversation
You need to change the Safe Links settings in the Microsoft 365 Defender portal or the Teams admin center, depending on your role. You must be a global administrator or a security administrator to make these changes.
- Check the current Safe Links policy
Go to Microsoft 365 Defender portal at security.microsoft.com. Sign in with an admin account. Navigate to Policies & rules > Threat policies > Safe links. Look for the policy that applies to your organization or to the guest users. The default policy is named “Default Safe Links policy.” - Edit the Safe Links policy to allow the URL
Select the policy and click Edit. In the “URL and file settings” section, find the “Block the following URLs” list. If your URL is listed there, remove it. If the URL is not listed, the block may come from the “Do not track user clicks” setting or the “Use Safe Links for email messages” setting. Review these settings and adjust them if needed. - Add the URL to the allowed list, if your policy supports it
Safe Links policies do not have a direct “allow list” for specific URLs. Instead, you can use the “Do not rewrite the following URLs” list in the same policy. This list prevents Teams from scanning those URLs. Add the full URL, for example https://example.com/page. You can also add the domain to allow all links from that domain. - Apply the policy to the affected guest users
If you have a custom Safe Links policy, make sure it is applied to the guest users. In the policy, under “Applied to,” add the guest users or the group that contains them. If you use the default policy, it applies to all users in your organization, including guests. - Test the link in a guest conversation
After saving the policy changes, wait up to 60 minutes for the changes to propagate. Then send the URL again in the guest chat. If the warning still appears, check the Microsoft 365 Defender portal under Reports > Threat protection > Safe links to see the block reason.
Alternative Fix: Use the Teams Admin Center to Disable Safe Links for Messaging
- Open the Teams admin center
Go to admin.teams.microsoft.com and sign in with an admin account. - Navigate to Messaging policies
In the left navigation, select Messaging policies under the Teams section. - Edit the policy that applies to your users
Select the Global (Org-wide default) policy or the policy assigned to the guest users. Click Edit. - Turn off Safe links for chats
Scroll to the “Safe links” section. Set “Safe links for chats” to Off. This disables URL scanning in Teams chats for users assigned this policy. Save the changes.
If Teams Still Blocks the URL After Changing Policies
Teams Shows the Warning Only for Guests, Not for Internal Users
If internal users can open the link but guests cannot, the block may come from the guest’s own tenant Safe Links policy. The guest’s organization scans the link on their side. You cannot change the guest’s policy. Ask the guest to contact their IT administrator to allow the URL or to disable Safe Links for Teams chats.
The Link Is Blocked Even After Removing It from the Block List
Safe Links also checks the URL against Microsoft’s global threat intelligence. If the URL has a bad reputation, it will be blocked regardless of your custom policy. In that case, you cannot unblock it. Use a different URL that points to the same content, or host the file on a trusted domain.
Policy Changes Take Time to Apply
Safe Links policy changes can take up to 60 minutes to propagate across all Microsoft 365 services. If you test immediately after saving, you may still see the old behavior. Wait at least an hour and then test again.
Safe Links in Teams vs Safe Links in Email: Key Differences
| Item | Safe Links in Teams | Safe Links in Email |
|---|---|---|
| Scanning trigger | When a user sends a message with a URL in a chat or channel | When an email is received with a URL in the body or attachment |
| User experience | Warning banner in the chat window, link not clickable | URL is rewritten and checked at click time |
| Policy location | Teams admin center > Messaging policies > Safe links | Microsoft 365 Defender portal > Safe links policy |
| Guest user effect | Guests are scanned with the host tenant policy, but their own tenant may also scan | Email is scanned by the sender’s and recipient’s policies |
Now you know how to fix a Safe Links warning that blocks a valid URL in a guest conversation. You can edit the Safe Links policy in the Microsoft 365 Defender portal, add the URL to the do-not-rewrite list, or disable Safe Links for chats in the Teams admin center. Remember that guest tenant policies can also cause blocks, and those require the guest’s IT admin to change. For a quick check, use the Safe Links report in the Defender portal to see why a link was blocked.