Microsoft’s latest wave of Microsoft 365 updates, rolling out to eligible tenants through August, has quietly added a feature that closes a gap plenty of UK small businesses didn’t know they had. URL time-of-click protection, previously reserved for higher-tier enterprise plans, is now rolling out to Basic and Standard business plans too. It rescans links in Outlook and Office apps at the exact moment someone clicks — not just when the email first arrives — which matters because a growing share of phishing attacks now register a link as clean at delivery time and only turn it malicious hours or days later, precisely to slip past arrival-time scanning.

It’s a small technical change with an outsized practical effect for smaller organisations, who are exactly the businesses least likely to have had this protection before now, and least likely to have IT resource dedicated to checking whether it’s actually switched on.

Why “clean on arrival” was never good enough

Traditional email security scans a link once, when the message lands in an inbox. Attackers have adapted to that reality by registering brand-new domains that pass every reputation check on day one, then activating the malicious payload only after the scanning window has passed — sometimes hours later, once a target has had time to open the email and click without a second thought. Time-of-click protection closes that gap by checking the link’s destination again, right as the click happens, rather than trusting a scan that might be stale. For a small business without a dedicated security team re-checking suspicious emails by hand, this shifts a meaningful chunk of that work back onto the platform itself.

What to check this week

The feature is rolling out automatically to eligible tenants, but “eligible” and “enabled” aren’t always the same thing — admin settings and existing Safe Links configurations can affect whether it’s actually active for your users. It’s worth an admin checking Microsoft 365 Defender settings directly rather than assuming the update has silently applied itself. It’s also a good prompt to check the basics that make any technical protection more effective: is multi-factor authentication enforced across every account, not just email, and do staff know to report a suspicious link rather than just deleting it? CoolCoding can review your current Microsoft 365 security configuration and confirm what’s actually switched on versus what’s just theoretically available on your licence tier.

A technical fix isn’t a training substitute

No amount of link-rescanning stops every attack — some phishing doesn’t rely on a malicious URL at all, using attachments, QR codes, or straightforward social engineering instead. Time-of-click protection is a genuinely useful extra layer, not a replacement for staff knowing what a suspicious request looks like, particularly around invoice changes, urgent payment requests, or anything asking for credentials outside a normal login flow. Layering the platform-level fix with five minutes of staff awareness covers considerably more ground than either alone.

This update also lands alongside a broader shift in how Microsoft is packaging Copilot across its business tiers, with more security and admin features that used to sit behind enterprise-only licences now trickling down to Basic and Standard. That’s generally good news for cost-conscious SMEs, but it also means the gap between what your licence technically includes and what your team is actually using tends to widen over time. Reviewing your Microsoft 365 admin centre every few months, rather than only when something breaks, is a cheap habit that catches this kind of drift before it matters.

The takeaway

If your business runs on Microsoft 365 Basic or Standard, this protection may already be live in your tenant without anyone having flipped a switch — which is good news, but also a reason to actually confirm it rather than assume it. A quick admin check this week costs nothing and closes a real, actively-exploited gap.