{"id":5885,"date":"2023-06-13T12:02:00","date_gmt":"2023-06-13T16:02:00","guid":{"rendered":"https:\/\/www.exchangedefender.com\/blog\/?p=5885"},"modified":"2023-06-16T15:16:10","modified_gmt":"2023-06-16T19:16:10","slug":"exchangedefender-phishing-firewall-and-microsoft-defender","status":"publish","type":"post","link":"https:\/\/www.exchangedefender.com\/blog\/2023\/06\/exchangedefender-phishing-firewall-and-microsoft-defender\/","title":{"rendered":"ExchangeDefender Phishing Firewall and Microsoft Defender"},"content":{"rendered":"\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing-1024x512.png\" alt=\"\" class=\"wp-image-5899\" srcset=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing-1024x512.png 1024w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing-300x150.png 300w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing-768x384.png 768w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing-1100x550.png 1100w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/XD-Phishing.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure><\/div>\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Now and then Microsoft Defender will encounter something potentially dangerous when it&#8217;s processing your browsing activity. Most of the time it is just the URL of a site they&#8217;ve blacklisted.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>Enter ExchangeDefender Phishing Firewall.<\/strong> We rewrite every URL going through our service to give our users an extra layer of security and prevent malware and phishing. If you&#8217;ve seen the&nbsp;<strong><a rel=\"noreferrer noopener\" href=\"http:\/\/xdref.com\/\" target=\"_blank\">xdref.com<\/a>&nbsp;l<\/strong>inks in your email, that&#8217;s US keeping you from accidentally clicking on a legitimate link and getting a zero-day exploit compromising your PC. Well, Microsoft Defender looks at the same link and its contents and can flag an entire URL of your phishing firewall. Then you end up seeing this:<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a href=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/xdref-defenderwarning.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/xdref-defenderwarning.png\" alt=\"\" class=\"wp-image-5887\" width=\"717\" height=\"597\" srcset=\"https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/xdref-defenderwarning.png 956w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/xdref-defenderwarning-300x250.png 300w, https:\/\/www.exchangedefender.com\/blog\/wp-content\/uploads\/2023\/06\/xdref-defenderwarning-768x639.png 768w\" sizes=\"auto, (max-width: 717px) 100vw, 717px\" \/><\/a><\/figure><\/div>\n\n\n<div style=\"height:34px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How do I get this resolved?<\/h2>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Since this URL is exclusively used by you and your clients, make sure you&#8217;re using ExchangeDefender Outbound Service to route outbound mail (our outbound service strips all the&nbsp;<a rel=\"noreferrer noopener\" href=\"http:\/\/xdref.com\/\" target=\"_blank\">xdref.com<\/a>&nbsp;URLs).<\/p>\n\n\n\n<p>Next, please report the problem with the URL to Microsoft at this location:<\/p>\n\n\n\n<p><a rel=\"noreferrer noopener\" href=\"https:\/\/security.microsoft.com\/reportsubmission?viewid=url\" target=\"_blank\"><strong>https:\/\/security.microsoft.com\/reportsubmission?viewid=url<\/strong><\/a><\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How do I fix it?<\/h2>\n\n\n\n<p>There are two ways to solve this problem within your tenant at Microsoft 365. The fastest way is with PowerShell:<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-black-color has-text-color has-background has-medium-font-size\" style=\"background-color:#ededed\"><strong>New-TenantAllowBlockListItems -ListType Url -Allow -Entries ~<a rel=\"noreferrer noopener\" href=\"http:\/\/xdref.com\/\" target=\"_blank\">xdref.com<\/a>~ -NoExpiration<\/strong><\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-black-color has-text-color\">The more user-friendly way to allow the URL is through the Microsoft Defender Portal at the following URL (make sure you&#8217;re logged in first):<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-black-color has-text-color has-background\" style=\"background-color:#ededed\"><a href=\"https:\/\/security.microsoft.com\/tenantAllowBlockList\"><strong>https:\/\/security.microsoft.com\/tenantAllowBlockList<\/strong><\/a><\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Microsoft tends to move its security components around a lot so if the URL changes login to the Microsoft 365 Defender Portal and go to: <strong>Policies &amp; Rules&gt; Threat Policies &gt; Rules section &gt; Tenant Allow\/Block Lists<\/strong>.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>To learn more<\/strong> about Microsoft Defender and how to manage its security policies on this topic please see the following <strong><a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/tenant-allow-block-list-urls-configure?view=o365-worldwide\">KB article<\/a><\/strong>.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>Tip: <\/strong>ExchangeDefender recommends executing this process when the client is onboarded, but it will work at any time.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n","protected":false},"excerpt":{"rendered":"<p> [&hellip;]<\/p>\n","protected":false},"author":50,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1,48],"tags":[],"class_list":["post-5885","post","type-post","status-publish","format-standard","hentry","category-exchangedefender","category-uncategorized","category-security"],"_links":{"self":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts\/5885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/comments?post=5885"}],"version-history":[{"count":14,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts\/5885\/revisions"}],"predecessor-version":[{"id":5905,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/posts\/5885\/revisions\/5905"}],"wp:attachment":[{"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/media?parent=5885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/categories?post=5885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.exchangedefender.com\/blog\/wp-json\/wp\/v2\/tags?post=5885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}