top of page
Search

Your Employee Clicked a Malicious Link in Teams — Would Microsoft Teams Phishing Protection Stop It?

Hanna Korotka
Sep 9
5 min read
Your Employee Clicked a Malicious Link in Teams — Would Microsoft Teams Phishing Protection Stop It?

Microsoft Teams has become part of the normal workday for many businesses. Employees use it to communicate with coworkers, join meetings, collaborate with external partners, and share files and links.


That familiarity can also create a security problem.


Imagine an employee receives a Teams message that looks routine:

“Can you review this document?”


There is a link underneath. The employee recognizes the sender's name, is busy, and clicks it.


But the link leads to a malicious website designed to steal credentials or other sensitive information.


Would Microsoft 365 stop the employee from opening it?


The answer depends on the protections available in your Microsoft 365 environment and how they are configured.


Malicious Links Aren't Just an Email Problem


Most employees have heard warnings about suspicious links in email. A Teams message can feel different.


A message might appear in a chat, group chat, channel, or meeting conversation, and users may be more inclined to trust it because Teams is viewed as an internal collaboration tool.


Microsoft specifically recognizes phishing as a threat in Teams. According to Microsoft's Teams security guidance, phishing attempts can use fake website links to trick users into providing passwords, codes, payment information, and other sensitive information.


The important point for SMBs is simple:

A link should not automatically be trusted just because it arrived through Microsoft Teams.


What Protection Does Microsoft Teams Already Provide?


Microsoft Teams includes built-in protection against known malicious URLs.


According to Microsoft, Teams provides near real-time URL protection in Teams messages.


When a known malicious URL is detected, Teams can add a warning to the message.


Protection does not stop after the message is initially delivered. Microsoft states that messages found to contain malicious URLs up to 48 hours after delivery can also receive a warning.


This is useful because the reputation of a URL can change after a message has already reached employees.


Microsoft's built-in malicious URL protection is available with Teams and does not require Microsoft Defender for Office 365.


However, there is an important distinction:

A warning about a malicious URL is not the same as blocking that URL when an employee clicks it.


For additional time-of-click protection, Microsoft provides Safe Links for Teams through Microsoft Defender for Office 365.


How Microsoft Teams Phishing Protection Works When Someone Clicks a Link


With Safe Links protection for Teams enabled, Microsoft checks URLs when a protected user clicks them.


Microsoft calls this time-of-click protection.


For example:

  1. An employee receives a link in a Teams chat.

  2. The employee clicks the link.

  3. Safe Links checks the URL against Microsoft's information about known malicious links.

  4. If the URL is identified as malicious, the employee is shown a warning page instead of simply being sent to the website.


Unlike Safe Links in email, URLs in Teams aren't rewritten. The link is evaluated when the protected user clicks it.


Safe Links supports links in Teams conversations, group chats, channels, and tabs, and Microsoft documents support across Teams desktop, web, Android, and iOS apps.


This extra check is valuable because a URL that appeared harmless when it was originally shared might later be identified as malicious.


Can Employees Ignore the Warning?


This is where configuration matters.


Safe Links policies include an option called Let users click through to the original URL.

If click-through is allowed, a user can choose to continue to a URL despite the Safe Links warning.


Microsoft recommends not enabling this option, which prevents users from clicking through to the original URL after it has been identified as malicious.


For an SMB, this is an important setting to review.


A security control is considerably less useful if an employee can simply dismiss the warning and continue to a known malicious site.


Is Safe Links for Teams Automatically Protecting Everyone?


Do not assume that every employee has the same protection without checking your policies and licensing.


Safe Links is part of Microsoft Defender for Office 365. Microsoft says that the Built-in protection preset security policy provides Safe Links protection for Teams to recipients who aren't otherwise covered by Standard, Strict, or custom Safe Links policies.


But there is an important configuration detail.


If your organization has custom Safe Links policies, those policies take precedence over Built-in protection. Microsoft therefore recommends checking that Teams protection is enabled in each applicable custom policy.


Administrators can review this in the Microsoft Defender portal under:

Email & collaboration → Policies & rules → Threat policies → Safe Links


For custom policies, look for the Teams setting:

“On: Safe Links checks a list of known, malicious links when users click links in Microsoft Teams. URLs are not rewritten.”


Microsoft recommends having this setting turned on.


Can You See When Employees Click Suspicious Links?


Protection is only part of the equation. Businesses also need visibility.


Microsoft Defender for Office 365 provides reporting for Safe Links activity.

Email & collaboration → Policies & rules → Threat policies → Safe Links → Reports


Microsoft notes that user click data depends on the Track user clicks setting in the effective Safe Links policy.


Organizations with the appropriate Defender capabilities can also investigate URL clicks through Threat Explorer and advanced hunting.


This gives security teams more information when investigating questions such as:

Did anyone click the malicious link?

Was the click blocked?

Which URL was involved?


That visibility can make a major difference when responding to a suspected phishing incident.


What Should an Employee Do With a Suspicious Teams Message?


Technology should not be your only defense.


Employees should be encouraged to stop before opening unexpected links, especially when a message asks them to sign in, provide information, make a payment, or take an unusual action.


Organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2, or Microsoft Defender XDR, can also allow users to report suspicious Teams messages. Administrators can review reported messages through the Microsoft Defender portal.


A simple internal rule can help:

If a Teams message or link seems unusual, verify it before interacting with it.


For example, if a coworker unexpectedly sends a link asking you to sign in, contact that person separately instead of trusting the message simply because it came from their Teams account.


A Quick Security Checklist for SMBs


If your organization relies heavily on Microsoft Teams, review these five areas:


1. Check malicious URL protection in Teams. Make sure your organization is benefiting from Microsoft's built-in warnings for malicious URLs.


2. Verify Safe Links protection for Teams. If you use Microsoft Defender for Office 365, check the effective Safe Links policies and confirm that Teams protection is enabled where applicable.


3. Review the click-through setting. Microsoft recommends preventing users from continuing to URLs that Safe Links identifies as malicious.


4. Review URL click visibility. Make sure your security team knows where to investigate URL activity and whether user click tracking is enabled in your Safe Links policies.


5. Give employees a way to report suspicious Teams messages. Employees should know what to do when a message, link, or request does not look right.


Microsoft Teams Is Part of Your Security Perimeter


For many SMBs, Teams is no longer simply a chat application. It is one of the main places where employees communicate, exchange files, meet external contacts, and make everyday business decisions.


That means Teams deserves the same security attention businesses traditionally give to email.


Microsoft provides built-in malicious URL warnings in Teams, while Microsoft Defender for Office 365 can add Safe Links time-of-click protection and additional investigation capabilities.


The important question isn't simply whether your organization owns Microsoft security tools.

It is whether the right protections are actually covering your users.


How We Can Help


We help SMBs review and manage their Microsoft 365 security configuration, including Microsoft Teams and Microsoft Defender for Office 365. We can verify Safe Links policies, review Teams protection settings, identify security gaps, and help ensure the Microsoft 365 security features available to your organization are configured appropriately.



 
 
 

Comments


Get the Latest News to Your Inbox

bottom of page