Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
Thank you for the clarification and for explaining why the message authentication and delivery path are relevant.
Just to clarify my position, I am raising this from the perspective of an SOC team using an email platform managed by a separate email security/administration team. I am not an administrator of the Microsoft 365 environment, so I do not have direct access to Defender Explorer, message trace, connector configuration, or the complete authentication information requested.
I have raised the issue internally; however, the detailed backend investigation information available to me remains limited.
For this reason, I would like to focus on one aspect that should be independently reproducible and publicly testable: legitimate VirusTotal URLs containing a malicious domain as part of the URL path.
For example:
https://www.virustotal.com/gui/domain/example[.]com
In this case, the actual destination is virustotal.com, while the potentially malicious domain appears only as part of the URL path for threat-intelligence lookup purposes.
The email security team has advised, based on its simulation, that Microsoft Defender for Office 365 Machine Learning may still recognise the malicious indicator within the URL and classify the message as phishing, even though the destination itself is VirusTotal.
This is the specific behaviour I would like to validate.
Is Defender for Office 365 expected to analyse the domain appearing within a VirusTotal URL path and use that indicator as part of the phishing verdict?
If so, is there a Microsoft-recommended way for SOC/security teams to include legitimate VirusTotal references in security notifications without those references contributing to a High Confidence Phishing classification?
I understand that sender authentication, reputation and delivery path can also influence the overall verdict. However, the VirusTotal example may provide a more generic scenario that can be tested independently without relying on access to our specific Microsoft 365 environment.
The clarification would also help us determine the appropriate next step internally whether this behaviour should be pursued further with Microsoft Support as a product-level detection issue, or whether there is a tenant-side configuration, policy, or mail-flow setting that should be reviewed and adjusted by the Microsoft 365 administration team.
Any clarification on how Defender handles this type of threat-intelligence URL, or any Microsoft-recommended configuration or best practice for this scenario, would be greatly appreciated.
Thank you again for your guidance.