Using New Outlook on Windows for personal email, calendar, and contact management
URL rewrites to force scanning on any device a end user is using to access company data seems to be a surefire way to get this warning from Microsoft, even though its a Microsoft certified email protection API. You may see a link with, for example "https://us-east-2.protection.sophos.com..."When you click it the safe scan happens then your redirected to the original URL.