Skip to main content

Outbound URL Whitelisting in Microsoft Defender for Endpoint

How to allow revel8 fake website domains in Microsoft Defender for Endpoint (SmartScreen) so simulation landing pages are not blocked when users click a simulation link.

🧭 1. Why This Step Is Needed

When a user clicks a revel8 simulation link, the email has already been delivered through Microsoft's email filters (handled by the Advanced Delivery policy). But there's one more check on the endpoint itself: Microsoft Defender SmartScreen, which evaluates the URL inside the browser. If SmartScreen flags a revel8 simulation domain as unsafe, the user sees a "This site has been reported as unsafe" warning and the simulation breaks.

To prevent this, all revel8 simulation domains need to be added as Allow indicators in Microsoft Defender for Endpoint.

💡 Which Microsoft products are involved?

  • Defender for Office 365 -> protects email (Advanced Delivery, Safe Links). Covered in the inbound whitelisting guide.

  • Defender for Endpoint -> protects the device. Runs SmartScreen on the browser. This is what this guide covers.

Both are managed from the same portal: security.microsoft.com.

⚠️ When to skip this guide

This step is only required if your organization uses Microsoft Defender for Endpoint (Plan 1 or Plan 2) with SmartScreen enabled. If you only use Defender for Office 365, you can skip this guide - the inbound whitelisting already covers your setup.

📋 2. Before You Start

revel8 uses multiple rotating simulation domains for credential phishing and other link-based simulations. Every domain ideally needs to be allowlisted.

Get the full list from the revel8 platform:

  1. Open the revel8 platform and go to IntegrationsWhitelisting.

  2. Copy every domain both of the following sections:

    • Fake Website Domains (phishing landing pages or trainings)

    • Safe Link Domains (further link-click domains)

  3. Toggle to active after the whitelisting has been completed.

💡 Why both lists?

SmartScreen evaluates any URL the browser loads. Depending on the simulation type, users may be redirected through a Safe Link domain or a Fake Website domain. If either is flagged, the simulation breaks. Adding both to the allow list ensures no URL is blocked at the endpoint.

🛠 3. Add revel8 Domains as Allow Indicators

  1. Go to security.microsoft.com and sign in as a Security Administrator or Global Administrator.

  2. In the left navigation, go to SettingsEndpoints.

  3. Under Rules, click Indicators.

  4. Select the URLs/Domains tab, then click Add item.

  5. Fill in the fields:

    • Indicator - Enter the revel8 simulation domain

    • Action - Select Allow.

    • Title - Use revel8 Simulation allowlist

    • Description - (optional) e.g. Allow list for revel8 phishing simulation URLs

  6. Under Scope, select All devices in my scope.

  7. Click Save.

  8. Repeat steps 4-7 for every active domain under Fake Website Domains and Safe Link Domains.

⚠️ Important: Changes may take up to 30 minutes to reach all endpoints.

Did this answer your question?