An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Advanced delivery plus a Safe Links bypass rule is the right direction, but there are a few Defender behaviors and configuration details that explain what is being seen.
Key points from the documented behavior:
- Advanced delivery does not fully disable Safe Links detonation in all cases
For non-Microsoft phishing simulations, advanced delivery ensures:- Filters take no action on the messages.
- ZAP for spam/phish takes no action.
- Safe Links “doesn't block or detonate the specified URLs in these messages at time of click. URLs are still wrapped, but they aren't blocked.”
- If using the Built-in protection preset or custom Safe Links policies with Do not rewrite URLs, do checks via SafeLinks API only enabled, time-of-click protection does not treat phishing simulation links as threats in:
- Outlook on the web
- Outlook for iOS and Android
- Outlook for Windows v16.0.15317.10000 or later
- Outlook for Mac v16.74 (23061100) or later
- If using older Outlook clients, the guidance is to disable the “Do not rewrite URLs, do checks via SafeLinks API only” setting in custom Safe Links policies so that simulations are handled correctly.
- Verify which Outlook clients are in use.
- Check Safe Links policies for the Do not rewrite URLs, do checks via SafeLinks API only setting and align it with the client versions as described above.
- Do not add simulation URLs to ‘Do not rewrite’ in Safe Links
The documentation explicitly warns:- Adding phishing simulation URLs to Do not rewrite the following URLs in email can cause unwanted alerts for URL clicks.
- Phishing simulation URLs are automatically allowed both during mail flow and at time of click.
- Remove phishing simulation URLs from the Do not rewrite the following URLs in email section in Safe Links policies.
- Rely on advanced delivery for the simulation scenario instead of manual URL bypass entries.
- Advanced delivery changes how user reports and alerts behave
For non-Microsoft phishing simulations configured in advanced delivery:- Admin submission generates an automatic response indicating the message is part of a phishing simulation and not a real threat; alerts and AIR are not triggered.
- When a user reports a phishing simulation message using the built-in Report button in Outlook:
- No alert, investigation, or incident is generated.
- Links/files are not detonated.
- The message appears on the User reported tab of the Submissions page.
- The simulation messages are not being correctly matched by the advanced delivery phishing simulation configuration (for example, mismatch in sending IP, domain, or header values), or
- The messages are not being treated as “Phishing simulation” system overrides.
- Re-check the advanced delivery Phishing simulation configuration in the Microsoft Defender portal (Email & collaboration → Policies & rules → Threat policies → Advanced delivery → Phishing simulation tab). Ensure the sender domain, IPs, and any header values exactly match what the simulation platform uses.
- In Threat Explorer / Real-time detections or the Email entity page, confirm that these messages show System override source = Phishing simulation. If they do not, adjust the advanced delivery configuration until they do.
- Avoid using mail flow rules (SCL -1) for phishing simulations
Documentation recommends:- For SecOps mailboxes or phishing simulations, use the advanced delivery policy instead of mail flow rules.
- SCL -1 rules are risky and do not bypass malware or high confidence phishing protections.
- Review mail flow rules in the Exchange admin center for any rules related to the simulation sender/domain/IP.
- Remove or narrow any SCL -1 or bypass rules and rely on advanced delivery for the simulation scenario.
- Do not disable intra-org scanning globally
For simulations within the same organization (DIR:INT) routed through an on-premises Exchange gateway, advanced delivery for non-Microsoft simulations is not supported. The documented workarounds are:- Create a dedicated Receive connector that does not authenticate the simulation messages as internal; or
- Configure the simulation platform to bypass the on-premises infrastructure and send directly to the Microsoft 365 MX record.
- It is not recommended to set intra-organization message scanning to None in anti-spam policies, as this affects all mail.
Summary of what to adjust:
- Confirm the simulation messages are correctly matched by the Phishing simulation advanced delivery configuration and show as Phishing simulation system overrides.
- Remove simulation URLs from Do not rewrite in Safe Links; do not rely on Safe Link bypass rules for simulations.
- Align the Do not rewrite URLs, do checks via SafeLinks API only setting with the Outlook client versions in use.
- Remove or narrow any mail flow rules used to bypass spam/Safe Links for the simulation; rely on advanced delivery instead.
- If using hybrid or internal simulations, ensure the documented routing/connector workarounds are in place so advanced delivery can apply.
References:
- Configure the advanced delivery policy for non-Microsoft phishing simulations and email delivery to SecOps mailboxes
- Secure by default in cloud organizations
- Troubleshoot common anti-spam policy issues
- Frequently asked questions - Anti-spam protection
- Attack simulation training deployment considerations and FAQ