You paste a link in a Teams chat, and a warning says the URL is unsafe. You know the link is valid, but Teams blocks it anyway. This often happens after an admin changes a compliance policy, such as a data loss prevention rule or a Safe Links policy. The block is not a mistake. Teams applies the new policy to every URL in chats and channels, and the link fails the policy check.
This article explains why a policy change causes the Safe Link warning to appear. It then shows you how to confirm the policy, how to allow a specific domain, and what to do if the warning still appears. You will also see the differences between Safe Links in Teams, Exchange Online, and SharePoint.
Key Takeaways: Safe Links Policy Changes in Teams
- Microsoft 365 Defender > Email & collaboration > Policies & rules > Threat policies > Safe Links: Shows the Safe Links policy that controls which URLs Teams allows in chats and channels.
- Safe Links policy > URL & click protection settings > Do not track user clicks: Disables the warning banner while still blocking malicious links.
- Safe Links policy > URL & click protection settings > Do not allow users to click through to the original URL: Forces the warning page, so you must turn this off to let users open the link.
- Tenant Allow/Block List > Allowed URLs: Lets you add a specific domain or full URL so Teams stops blocking it.
- Teams admin center > Messaging policies > Safe links: Controls whether Safe Links applies to Teams messages; turn this off only if the URL is safe and the block is a false positive.
Why Teams Blocks a Valid URL After a Compliance Policy Change
Safe Links is part of Microsoft Defender for Office 365. It scans every URL that a user clicks in an email, a SharePoint document, or a Teams message. When a link matches a blocked domain or a known malicious pattern, Teams shows a warning page instead of opening the URL.
A compliance policy change can cause a false positive. For example, an admin might update a data loss prevention rule that blocks URLs containing certain keywords. Or the admin might add a new Safe Links policy that applies to all Teams chats. When the policy is saved, Teams immediately re-evaluates every link that a user sends. If the URL contains a word that the policy flags, the warning appears even though the link is safe.
Another cause is the Safe Links policy settings themselves. Two settings control the warning behavior:
- Do not track user clicks — when this is on, Teams does not record click activity, and the warning banner may not appear.
- Do not allow users to click through to the original URL — when this is on, Teams forces the warning page and blocks the click.
If the admin enables the second setting, every URL that fails the policy check shows the warning. The fix is to adjust the policy or add the URL to an allow list.
Steps to Confirm the Safe Links Policy That Is Blocking the URL
- Open the Microsoft 365 Defender portal
Go to security.microsoft.com and sign in with an account that has the Security Administrator or Global Administrator role. - Open the Safe Links policy list
In the left navigation, select Email & collaboration then Policies & rules then Threat policies. Under Policies, select Safe Links. - Identify the policy that applies to Teams
The list shows all Safe Links policies. The default policy is named Office365 SafeLinks. Look for the policy that has Teams listed in the Applied to column. If no policy shows Teams, the default policy applies. - Check the URL protection settings
Select the policy name to open the details pane. Scroll to URL & click protection settings. Note whether Do not allow users to click through to the original URL is on. This setting causes the warning page to appear. - Check the block list for the exact URL
In the same details pane, select Custom notification and then Edit. Look for the Block the following URLs list. If your URL is there, the policy is blocking it directly.
How to Allow a Valid URL That Safe Links Blocks
After you confirm the policy, you have two ways to fix the block. You can add the URL to the Tenant Allow/Block List, or you can turn off the click-through block for the whole policy. The first method is safer because it only allows the specific URL.
Method 1: Add the URL to the Tenant Allow/Block List
- Open the Tenant Allow/Block List
In Microsoft 365 Defender, go to Policies & rules then Threat policies then Tenant Allow/Block List. - Create a new entry
Select the URLs tab, then select Add. Choose Allow as the action. - Enter the URL or domain
Type the full URL, for example https://contoso.com/reports/q2.pdf. You can also enter a bare domain like contoso.com to allow all subdomains. Select Add. - Set the expiration
Choose Never expire if the URL is permanent, or set a date. Select Save. - Test the link in Teams
Paste the URL in a Teams chat and send it. The warning should no longer appear.
Method 2: Turn Off the Click-Through Block in the Safe Links Policy
- Open the Safe Links policy
In Microsoft 365 Defender, go to Threat policies then Safe Links and select the policy that applies to Teams. - Edit the URL protection settings
Select Edit next to URL & click protection settings. - Clear the click-through block
Uncheck Do not allow users to click through to the original URL. Leave Do not track user clicks unchecked so Teams still logs clicks. - Save the policy
Select Save. The change takes effect within 30 minutes. - Test the link again
Send the URL in a Teams chat and click it. The warning should no longer appear.
If Teams Still Shows the Warning After the Policy Fix
Sometimes the policy change is not the only cause. The warning can also come from a data loss prevention rule or from the Teams messaging policy. Check these areas if the block persists.
Teams Still Blocks a URL After Adding It to the Allow List
The Tenant Allow/Block List takes up to 30 minutes to apply. If you tested immediately, wait and try again. Also confirm that the URL you entered matches the exact format that Teams sees. For example, if the link uses http instead of https, add both versions. If the link contains a redirect, add the final destination URL.
A Data Loss Prevention Rule Blocks the URL
Data loss prevention rules scan URLs for sensitive content. A rule might block a URL that contains a credit card number or a passport number. Open the Microsoft Purview compliance portal, go to Data loss prevention, and review the rules that apply to Teams. If a rule is too broad, edit it to exclude the specific URL or domain.
The Teams Messaging Policy Has Safe Links Disabled
If Safe Links is disabled in the Teams messaging policy, Teams does not scan URLs at all. That means the warning should not appear. If it still appears, the block comes from another source, such as an Exchange Online Safe Links policy. Check the Exchange admin center to see if the URL is blocked there.
Safe Links in Teams vs Exchange Online vs SharePoint: Key Differences
| Item | Teams | Exchange Online |
|---|---|---|
| Where it applies | Chats and channels | Email messages |
| Policy location | Microsoft 365 Defender Safe Links policy | Microsoft 365 Defender Safe Links policy |
| Click tracking | Controlled by Do not track user clicks | Controlled by Do not track user clicks |
| Allow list | Tenant Allow/Block List | Tenant Allow/Block List |
| User warning behavior | Warning page blocks the click | Warning page blocks the click |
| Admin control | Teams admin center messaging policy can disable Safe Links | Exchange admin center mail flow rules can override |
SharePoint uses the same Safe Links policy but applies it to documents. The allow list is shared across all three services, so adding a URL in the Tenant Allow/Block List fixes the block in Teams, email, and SharePoint.
What to Do Next After Fixing the Safe Link Warning
You can now allow a valid URL that Safe Links blocks after a compliance policy change. You also know how to check the policy settings and how to use the Tenant Allow/Block List to permit a specific domain.
Test the fix by sending the URL in a Teams chat and clicking it. If the warning still appears, check the data loss prevention rules and the Exchange Online Safe Links policy. For a permanent solution, add the domain to the Tenant Allow/Block List with a long expiration date. You can also use the Ctrl+F5 shortcut in Teams to refresh the client and clear cached policy data.