Which Defender Protects Against Malicious Links in Email, Chat, and Channels?

Answer Correct answer: B — Microsoft Defender for Office 365 uses Safe Links scanning and time-of-click URL verification to protect email, Teams chats, and channels from malicious links.

What can you use to protect against malicious links sent in email messages, chat messages, and channels?

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Defender for Office 365 Correct Answer
  3. Microsoft Defender for Endpoint
  4. Microsoft Defender for Identity

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests which Defender workload handles Safe Links for email and Microsoft Teams collaboration traffic, and the trap is confusing the other Defender products (Cloud Apps, Endpoint, Identity) that each protect a different surface.

Safe Links in Microsoft Defender for Office 365 scans and rewrites URLs and re-checks them at click time across email, Teams chats, and channels. This page confirms why option B is the SC-900 answer and why the other Defender workloads do not cover malicious link protection in messaging.

The most common wrong pick is Microsoft Defender for Cloud Apps (A), because it is also a Defender-branded cloud security service; however it is a CASB for SaaS discovery, session control, and app anomalies, not the Safe Links engine that detonates and rewrites URLs in email and Teams.

Community Discussion (3 comments)

KindFlame 👍 1 Selected: B
Correct Answer: Microsoft Defender for Office 365
LegendaryZA 👍 2 Selected: B
Answer: Microsoft Defender for Office 365
chiliman 👍 4 Selected: B
To protect against malicious links in email messages, chat messages, and channels, Microsoft offers Safe Links in Microsoft Defender for Office 365. This feature provides URL scanning and rewriting of inbound email messages during mail flow, and time-of-click verification of URLs and links in email messages, Teams, and supported Office 365 apps.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Office 365 is the workload that delivers Safe Links, which rewrites inbound URLs during mail flow and performs time-of-click verification of links in email, Microsoft Teams messages, and channels. Because a malicious link can be sent clean and weaponized later, detonation-on-click is exactly the control the scenario describes. Safe Links also covers supported Office apps such as Word, Excel, and PowerPoint, keeping the protection consistent wherever a user clicks. That makes B the only option that maps directly to "malicious links in email messages, chat messages, and channels."

Why the Other Options Are Wrong

Microsoft Defender for Cloud Apps (A) is a Cloud Access Security Broker focused on shadow IT discovery, SaaS session policies, and anomalous behaviour in cloud apps, and it does not rewrite or detonate URLs inside Exchange mail flow or Teams chats. Microsoft Defender for Endpoint (C) is endpoint detection and response, protecting devices from malware and post-exploitation behaviour rather than screening message-borne links. Microsoft Defender for Identity (D) monitors on-premises Active Directory signals for identity-based attacks and has no URL reputation component at all.

Community Comment Notes

Every learner record on this page selects B, and the reasoning is consistent with the vendor documentation. As chiliman explains, the feature behind the scenario is Safe Links, offering "time-of-click verification of URLs and links in email messages, Teams" plus scanning and rewriting of inbound mail. LegendaryZA and KindFlame simply confirm the same pick with no dissent, so the community consensus and the technical analysis agree here.

Official Reference

Exam Strategy

Anchor the four Defender workloads to their protection surface: Office 365 = email and collaboration, Endpoint = devices, Identity = on-prem AD, Cloud Apps = SaaS apps. Any SC-900 question mentioning links, attachments, phishing, or Teams chat safety is pointing at Defender for Office 365.

Frequently Asked Questions

Why is Microsoft Defender for Cloud Apps wrong for malicious links in Teams?

Defender for Cloud Apps is a CASB that discovers SaaS usage and applies session or anomaly policies; it does not rewrite or detonate URLs inside email and Teams messages the way Safe Links does.

Does Safe Links protect links in Microsoft Teams channels and chats?

Yes. Safe Links covers email plus Microsoft Teams messages, channels, and supported Office apps, applying time-of-click verification so a link weaponized after delivery is still blocked.

Related Analysis

Practice All SC-900 Questions

Access 141 questions with complete answers and detailed explanations.

View Full SC-900 Practice Test →

← Back to SC-900 Study Guide