Hello all,
We have been applying a signature too all our users emails for years which included a URL that uses an API to create a vCard so the recipient can add to contacts easily (I know, management request)
This has been working for years, but as of yesterday Defender has suddenly decided it is malicious and any email with this link in the signature is getting quarantined in our tenant but also other external tenants so we effectively can not send or receive any email, as all emails have this link either in the original email or in the reply.
We have removed this link from the signature and have whitelisted it in our tenant so we can now receive emails. The problem is if any user replies to an existing email chain which has this URL in it from a previous reply the receiving tenant quarantines the email. We cannot send emails without creating a new email chain that doesn't contain this link.
Obviously we cannot whitelist the URL in other tenants, so any ideas why Defender suddenly decided this url is malicious and how we can send emails again that contain it? Stripping the URL out of outbound emails would work, but not sure if this is even possible.