Using Power Automate to save email attachments - safe from phishing?

Boltwood, Audrey 0 Reputation points
2025-01-03T20:58:31.7833333+00:00

At my job, I frequently receive many invoices that I need to attach to expense reports, so I created a Power Automate flow that saves all attachments from emails that A) Come from specific email addresses from which I frequently receive invoices AND B) Have the word "Invoice" in the subject line. The attachments are saved to a folder in my Business OneDrive and it's very handy.

But my question is, is this a potential security risk? If one of the email addresses were to be hacked and send me a fake invoice attachment, wouldn't it automatically download the malicious file? Is this something that Microsoft has addressed? Are there any anti-phishing "checks" I can add to my Power Automate flow to make it safer? Thanks in advance!

OneDrive
OneDrive
A Microsoft file hosting and synchronization service.
1,235 questions
Microsoft Power Platform Training
Microsoft Power Platform Training
Microsoft Power Platform: An integrated set of Microsoft business intelligence services.Training: Instruction to develop new skills.
519 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.