Linking directly to files and folders in Teams is convenient and helps people work efficiently, but it can also train users to click links in email without thinking. How do you balance that productivity benefit with the security risks of malicious or compromised links?
2 Answers
An email security platform can handle much of this automatically. For example, URL-protection features can inspect links at click time, block known malicious destinations, and sometimes detect newer attack methods such as QR-code phishing. It’s worth checking whether your existing email provider offers this or evaluating a dedicated security service.
Exactly. A blanket ban may reduce some risk, but it can also be impractical when normal business workflows depend on shared documents. Strong filtering, user training, clear reporting procedures, and requiring users to verify unexpected requests usually provide a more workable balance.
Use layered protection rather than relying only on a policy telling people never to click links. Email security tools can rewrite and analyze URLs when messages arrive, while secure web gateways or endpoint protection scan the destination when a user opens it. Make sure those controls cover remote workers and company-managed devices too.

So the recommendation is to allow link clicks with inspection and filtering in place? Some organizations instead have a blanket policy against clicking links in email.