Someone sent me a SharePoint or OneDrive link. Is it safe because it is Microsoft?
Microsoft branding has become a security problem precisely because it is so trusted. Anyone can build a page that looks exactly like a Microsoft sign in screen, and plenty of attackers do, because it is the fastest route to a working business email password.
There are two different things that get confused here. A genuine SharePoint or OneDrive share from someone you work with is normal and fine. A link that merely looks like SharePoint, sent by someone you do not have an established relationship with, is a common phishing pattern.
A few practical checks. Be suspicious of urgency language attached to a document, especially wording like one time access, single use, or expiring link. That framing exists to make you act before you think. Be more suspicious when the document arrives from someone you have never worked with, or when a file appears in a conversation where no file was needed.
The most reliable habit is simple: never sign in from a link in an email. If a document genuinely lives in Microsoft 365, you can open your browser, go to office.com or your normal portal yourself, sign in there, and find it. If it does not exist when you get there under your own steam, it was never real.
If you already typed your password into a page you reached from an email link, treat that as the real event. Change the password from a device you trust, confirm multi-factor authentication is on, check your mailbox rules for anything forwarding your mail, and let your IT provider review recent sign in activity.
Want a straight answer about your setup?
Asheville Computer Company is a local managed IT provider based in Arden, minutes from most of Asheville.
Call (828) 290-9092 or visit ashevillecomputercompany.com for a free, no-pressure consultation.