A phishing link hosted on OneDrive reached harper.morgan through Microsoft Teams around 12:03 UTC. At 12:13:44 the user clicked it and Microsoft Defender allowed the click. Fourteen seconds later Microsoft classified the message as phishing and removed it. The removal was too late to stop the click.
Fluency flagged this alert as the first of its kind in the organization and the first for this user, which is why it scored Critical. Our assessment: about 80% likely a real security issue. What remains unknown is whether the user entered a password or downloaded a file. The next step is to review this user's sign-ins and device activity after 12:13 UTC.
What Fluency's AI Assistant already concluded
Fluency AI Assistant triage · built on in this report
Escalate to Tier TwoValidatedActionableEvidence quality: moderate
"Malicious URL click by harper.morgan@acmeinc.com was allowed at time of click and later flagged by MDO. No mitigation observed. Immediate escalation to Tier Two is recommended for containment, forensic triage, credential/session review, and tenant-wide remediation."
Agreed: the click was real, allowed, and later identified as malicious; the case is actionable and belongs with Tier 2.
Corrected: the triage said "no mitigation observed". The captured events show Microsoft did remove the message (quarantined as Phish, Malicious), but 14 seconds after the click.
Answered: the AI asked why the delivery time (12:03) is earlier than the click (12:13). It's the normal order: delivered, then clicked, then removed.
Still open from its questions: whether credentials were entered or files downloaded; which device was used; sign-ins after the click; the destination page behind the link.
A high-severity Microsoft Defender alert: the user clicked a URL later identified as malicious, and the click was allowed. New to the organization and to the user, so the score was amplified.
What we could have alerted on
Candidate rule
Why it would help
Click before removal
Link a "message removed after delivery" event to a click on the same link by the same user. Today the removal is informational and creates no behavior, so the case under-states that the user was exposed before cleanup.
Phishing through Teams
Treat Teams-delivered phish as its own signal. Many users trust chat more than email.
Trusted-host phishing
Raise OneDrive and SharePoint share links that Microsoft classifies as phish; trusted domains get past URL reputation checks.
Suspicious sign-in after a malicious click
A new IP, device or MFA prompt for the same user within hours of the click. Needs Entra ID sign-in data, which is absent here.
Download or process after the click
EDR activity on the clicking device. Needs endpoint telemetry, which is absent here.
Verdict: real issue vs. benign
Real issue ~80%~15%5%
Red: likely a real issue. Green: likely benign. Gray: indeterminate.
Likely a real issue (~80%)
Microsoft classified the message Phish, Malicious and removed it; it wasn't just a reputation warning.
The user clicked and the click was allowed before removal.
OneDrive hosting and Teams delivery are a known way to get past email and URL filters.
First time this alert has fired in the organization, and first for this user: this isn't routine noise.
Fluency's AI triage independently validated it and escalated to Tier 2.
Likely benign (~15%)
Safe Links can misclassify legitimate OneDrive shares.
A click alone doesn't mean compromise: the user may have closed the page without entering anything.
There's no sign of follow-on activity in this data. That is absence of data, not proof: no sign-in or device records were present.
Recommended next steps
Review Entra ID sign-ins for harper.morgan after 12:13 UTC: new IPs, devices or MFA prompts. If anything is unusual, revoke sessions and reset the password. This is the check most likely to settle the verdict.
Check the device used for the click: EDR telemetry and any downloads. Clients with a Tenable One MCP can also check whether that endpoint is exposed or vulnerable, which is context Fluency doesn't hold.
Block and report the OneDrive share, and confirm no other user received or clicked it.
Ask the user what the page showed and whether they entered anything.
Method. Read-only investigation of tenant expo through the Fluency MSSP MCP: get_case, expand_case (2 records captured, retained to Oct 12, 2026) and describe_expanded_case (evidence marked sufficient), plus summarize_signature_attack_coverage. No case state, verdict or mapping was written to Fluency. ATT&CK mappings are inferred. The likelihood percentages are an analyst estimate, not a Fluency output. Times are UTC. Expo is a demonstration tenant: its records are sanitized replays of real activity, with the organization shown as Acme Inc. Prepared Sep 28, 2026.