Basically its a URL wrapper that provides continuity for the user, so if they dont have a threat intel database entry for the site, they let the user go there. They scan in the background as hemko said above to determine maliciousness.
Worth mentioning they do it for email too if you have it enabled.
Some documentation to add to this: https://learn.microsoft.com/en-us/defender-office-365/safe-links-about
Basically its a URL wrapper that provides continuity for the user, so if they dont have a threat intel database entry for the site, they let the user go there. They scan in the background as hemko said above to determine maliciousness.
Worth mentioning they do it for email too if you have it enabled.