This phish spoofed the recipient’s email address. It tries to use Microsoft branding to make the email look like a Microsoft Planner notification, even going so far as to make all of the blue links go to legitimate Microsoft Planner pages. However, the green “Open in Microsoft Planner” is a different story–it goes to a feedproxy.google.com URL, which is a red flag in this context.
While feedproxy.google.com itself isn’t a phish site, that service is used to redirect visitors to other sites, so the final destination is likely to be completely different and untrustworthy. The phisher has used a legitimate redirect URL to hide the real malicious destination.