Sharing links to Teams folders and files by email is extremely convenient and helps people work efficiently. The downside is that it can train users to click links in messages, which is also a common tactic in phishing attacks. How do you manage that trade-off while keeping collaboration easy and secure?
2 Answers
A dedicated email security service can handle this. For example, some platforms provide URL protection that analyzes links at click time and can also inspect QR codes, which are increasingly used in phishing campaigns. It’s worth checking whether your existing provider offers that capability or evaluating one if you don’t currently have it.
Use URL rewriting and scanning through your email security platform and secure web gateway. Links can be checked when the message arrives and again when someone clicks them, including when employees are working remotely on company-managed devices.

So the approach is to let users click links, but put protection and scanning around those clicks? Some organizations instead have a blanket policy telling people never to click links in email, so I’m curious how others decide between usability and that stricter rule.