Microsoft Safe Links
Connect Microsoft Safe Links to Radiant Security to forward click events for AI triage.
Last updated
Was this helpful?
Connect Microsoft Safe Links to Radiant Security to forward click events for AI triage.
Microsoft Safe Links is a Microsoft Defender for Office 365 capability that rewrites URLs in inbound email and performs time-of-click verification to block users from reaching malicious links. Enabling the Safe Links data feed on your existing Microsoft O365 connector forwards click events to Radiant Security. Radiant uses these events for AI triage, giving analysts visibility into phishing links accessed from unmanaged devices and identifying users who clicked from personal machines.
For background on the feature, see Safe Links in Microsoft Defender for Office 365.
Sign in to the Microsoft Defender portal.
In the left sidebar, navigate to Email & collaboration > Policies & Rules.
Click Threat policies, then select Safe Links.
Click + Create to add a new policy and add all users, groups, or domains to monitor. The screenshot below shows the mandatory and preferred settings:
Mandatory settings (outlined in red):
On: Safe Links checks a list of known, malicious links when users click links in email. URLs are rewritten by default.
Apply Safe Links to email messages sent within the organization
Preferred settings (outlined in blue):
Track user clicks
Let users click through to the original URL

Leave all other settings unchanged, then click Submit.
Once enabled, Microsoft rewrites all email links with the Safe Links prefix https://nam01.safelinks.protection.outlook.com.
Sign in to Radiant Security.
From the navigation menu, click Settings > Data Connectors.
Locate the row for the Safe Links data feed under your existing Microsoft O365 connector.
On the right side of the row, click Enable.
After Safe Links begins forwarding, confirm events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"ms365_safe_links".
Confirm recent events appear.
Allow several minutes for events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?