Using Power Automate to save email attachments - safe from phishing?

Boltwood, Audrey 25 Reputation points
2025-01-03T20:58:31.7833333+00:00

At my job, I frequently receive many invoices that I need to attach to expense reports, so I created a Power Automate flow that saves all attachments from emails that A) Come from specific email addresses from which I frequently receive invoices AND B) Have the word "Invoice" in the subject line. The attachments are saved to a folder in my Business OneDrive and it's very handy.

But my question is, is this a potential security risk? If one of the email addresses were to be hacked and send me a fake invoice attachment, wouldn't it automatically download the malicious file? Is this something that Microsoft has addressed? Are there any anti-phishing "checks" I can add to my Power Automate flow to make it safer? Thanks in advance!

Microsoft 365 and Office OneDrive For business Windows
0 comments No comments
{count} vote

Accepted answer
  1. Kiran P 8,220 Reputation points Microsoft External Staff Volunteer Moderator
    2025-01-06T04:03:43.5866667+00:00

    Hi Boltwood, Audrey,

    Thank you for reaching out to us on the Microsoft Q&A forum.

    This topic is not currently supported within the Q&A forums. We recommend starting a new discussion in the Microsoft Power Automate Community, where moderators and community members are available to provide guidance and assistance.

    If the information is helpful, please Accept Answer & Upvote so that it would be helpful to other community members.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.