News & Events

Your Microsoft 365 Tenant Isn’t Secure by Default: What Law Firms, Medical Practices, and Accounting Firms Must Lock Down Now

A new Microsoft 365 tenant can be created in minutes.

A secure, defensible Microsoft 365 environment cannot.

If your firm handles privileged legal files, protected health information, tax records, financial data, or confidential client communications, you cannot assume that creating a tenant, or turning on basic MFA, solves your security obligations.

You still need to configure:

  • Strong MFA enforcement
  • Conditional Access
  • Endpoint security
  • Email and phishing protection
  • Data loss prevention
  • Encryption and secure sharing
  • Identity governance
  • Backup and tested recovery
  • Monitoring and incident response

Microsoft 365 provides powerful security tools. It does not automatically configure your business around the risks you face.

That distinction matters for law firms, medical practices, accounting firms, financial advisors, and other organizations subject to regulatory or contractual security requirements.

The “Hey Margaret!” Problem

“Hey Margaret! I need you to send me the wire instructions again.”

The email appears to come from a managing partner, physician, client, or executive. The request is urgent. The tone feels familiar. The signature looks right.

Except it is not really from them.

This is how business email compromise begins. It can lead to diverted settlements, fraudulent payments, stolen tax records, exposed medical information, and ransomware.

Sometimes the attacker does not need sophisticated malware. A stolen password, an unmanaged laptop, or a convincing phishing message may be enough.

The common response is often:

“Hey, I got a guy who can look at it.”

That may be acceptable for a printer problem. It is not an adequate cybersecurity strategy for a regulated business.

Your technology environment needs documented policies, consistent configuration, continuous monitoring, and someone accountable for improving it over time.

Microsoft 365 Security Defaults Are a Starting Point: not a Complete Program

Microsoft does provide security defaults in Microsoft Entra ID. They establish a baseline that can require MFA registration, protect administrator accounts, block legacy authentication, and add safeguards against common identity attacks.

That is valuable.

But Microsoft also explains that organizations with more complex security requirements should consider Conditional Access instead. Security defaults are essentially on or off. They do not provide the policy-level control many professional-services firms need.

For example, your firm may need to:

  • Require MFA for every user and every cloud application
  • Require compliant, managed devices for access to sensitive files
  • Block sign-ins from high-risk locations
  • Apply stronger authentication to administrators and financial staff
  • Restrict access based on device health, application, location, and risk
  • Require reauthentication for sensitive actions

That is where Conditional Access becomes central to a Zero Trust strategy.

Microsoft describes Conditional Access as its Zero Trust policy engine. In plain English, it evaluates who is signing in, what they are trying to access, the device they are using, and the risk surrounding the request.

The question is no longer, “Is this person inside the office?”

The question becomes, “Can we verify this person, this device, this application, and this request right now?”

Law firm partner and IT consultant reviewing identity access policies

1. Lock Down Identity and Access First

Identity is the front door to Microsoft 365.

If an attacker controls a user account, they may gain access to email, OneDrive, SharePoint, Teams, contacts, calendars, and sensitive business applications.

Your baseline should include:

  1. MFA for every user
    Partners, attorneys, clinicians, reception staff, contractors, and administrators all require protection. Attackers frequently target ordinary users because their accounts may provide an easier path into the environment.

  2. Separate administrator accounts
    Administrators should not use highly privileged accounts for routine email and web browsing.

  3. Blocked legacy authentication
    Older protocols such as POP, IMAP, and SMTP AUTH may bypass modern MFA controls. They should be identified and disabled or tightly controlled.

  4. Conditional Access policies
    Use policy-based access rather than relying only on per-user MFA settings.

  5. Emergency access accounts
    Maintain carefully protected break-glass accounts for recovery if administrators are locked out.

  6. Identity governance
    Review access regularly. Remove former employees promptly. Control guest accounts. Use least-privilege access for applications, files, and administrative roles.

MFA is essential, but MFA alone is not Zero Trust. A stolen session token, compromised device, or excessive user permissions can still create risk.

2. Require Managed, Secure Devices

Your data does not become safe simply because it is stored in Microsoft 365.

A law firm attorney may access client files from a personal laptop. A medical practice employee may use a home computer to review patient information. An accountant may download tax documents to an unmanaged device.

That creates a problem.

You may not know whether the device is encrypted, patched, protected against malware, or shared with other people.

Endpoint security and Microsoft Intune help you establish a consistent standard across laptops, desktops, and mobile devices.

Your policies should address:

  • Full-disk encryption
  • Screen-lock requirements
  • Operating system and application updates
  • Endpoint detection and response
  • Antivirus and anti-malware protection
  • Remote lock and wipe
  • Device inventory
  • Restrictions on removable media
  • Separation of business and personal data
  • Access based on device compliance

The goal is not to make employees’ jobs harder. The goal is to prevent an untrusted device from becoming a shortcut into your client or patient data.

3. Harden Email Security and Data Sharing

Email remains one of the most effective attack channels because it combines urgency, trust, and human judgment.

Microsoft 365 should be configured with more than basic spam filtering.

Review and strengthen:

  1. Defender for Office 365 protections
    Use Safe Links, Safe Attachments, impersonation protection, and appropriate anti-phishing policies where your licensing supports them.

  2. SPF, DKIM, and DMARC
    These controls help prevent criminals from spoofing your domain and sending fraudulent messages that appear to come from your firm.

  3. High-risk user protection
    Executives, managing partners, finance staff, payroll administrators, and anyone who can authorize payments deserve additional scrutiny.

  4. Secure external sharing
    Restrict anonymous links. Require expiration dates. Limit sharing to approved domains where appropriate.

  5. Data Loss Prevention
    Use Microsoft Purview DLP to identify and protect sensitive information such as Social Security numbers, financial account data, patient information, and confidential client records.

  6. Sensitivity labels and encryption
    Apply stronger controls to information that should not be freely forwarded, downloaded, printed, or shared.

For law firms, the ABA’s guidance on securing communications recognizes that ordinary email may be appropriate for routine communications, while highly sensitive information may require encryption or a secure portal. Your firm should have a clear policy for deciding which channel to use.

4. Protect Medical, Financial, and Client Information

Different industries have different obligations, but the technical expectations overlap considerably.

Law firms

Lawyers have professional duties relating to confidentiality, competence, supervision, and technology. ABA Formal Opinion 477R emphasizes a risk-based approach to protecting client information transmitted electronically.

That means your firm should be able to demonstrate reasonable efforts: not just say, “We use Microsoft 365.”

Medical practices

HIPAA requires covered entities to conduct a risk analysis and implement safeguards addressing access control, audit controls, authentication, and transmission security.

Microsoft 365 may support HIPAA-aligned safeguards, but HIPAA compliance is not automatic. Configuration, policies, training, vendor agreements, and ongoing monitoring all matter.

Medical practice administrator reviewing endpoint security controls with a cybersecurity professional

Accounting firms and financial advisors

Many tax preparation firms, accounting firms, and certain financial advisors fall within the FTC Safeguards Rule.

The FTC requires covered businesses to maintain a written information security program appropriate to their size, complexity, and the sensitivity of the information they handle. The requirements include access controls, encryption, MFA, monitoring, employee training, service-provider oversight, and an incident response plan.

If your firm is subject to the Rule, “our email is in Microsoft 365” is not the same as having a documented security program.

5. Build Ransomware Protection and Business Continuity

Security controls reduce the likelihood of a successful attack. They do not eliminate risk.

You also need a plan for when something goes wrong.

Microsoft 365 includes retention and recovery features, but those features are not always a complete backup strategy for every business. You should determine:

  • What data must be recovered
  • How quickly it must be restored
  • How long it must be retained
  • Who can authorize restoration
  • Whether backups are isolated from administrative compromise
  • How often recovery is tested
  • How legal holds, medical records, and financial retention rules affect recovery

A backup that has never been tested is an assumption.

A documented, tested recovery process is part of business continuity and ransomware protection.

Should You Manage This Internally? Pros and Cons

Some firms can manage Microsoft 365 security internally. If you have experienced staff, clearly assigned ownership, adequate licensing, and time for continuous review, internal management can provide direct control.

But consider the tradeoffs.

Potential advantages

  • Direct oversight
  • Existing familiarity with your systems
  • No external service-provider transition
  • Internal control over priorities

Potential disadvantages

  • Training and certification costs
  • Dependence on one or two employees
  • Difficulty maintaining 24/7 monitoring
  • Missed configuration changes
  • Employee turnover
  • Limited incident-response capacity
  • Competing priorities during busy seasons

Cybersecurity is not a one-time installation. It is closer to medical care.

You need an initial assessment, a treatment plan, monitoring, follow-up, and a response when symptoms change.

That is why many firms choose managed IT for law firms, medical practice IT, or accounting firm IT from a provider that can own both daily support and long-term security improvement.

A Practical Microsoft 365 Lockdown Checklist

Start with these actions:

  1. Confirm whether security defaults or Conditional Access is protecting your tenant.
  2. Enforce MFA for every user and administrator.
  3. Block legacy authentication.
  4. Review global administrators and remove unnecessary privileges.
  5. Deploy Intune and require compliant devices for sensitive access.
  6. Encrypt laptops and mobile devices.
  7. Configure Defender email protections and impersonation policies.
  8. Publish SPF, DKIM, and DMARC for every sending domain.
  9. Review external sharing across SharePoint, OneDrive, and Teams.
  10. Configure DLP, retention, audit logging, and sensitivity labels.
  11. Verify backup coverage and test restoration.
  12. Document your incident response plan.
  13. Review access when employees change roles or leave.
  14. Measure improvement using Secure Score and regular risk assessments.

Accounting and financial professionals discussing secure email and business continuity

Final Word

Microsoft 365 is a powerful platform. It can support modern email security, endpoint security, identity governance, HIPAA-aligned safeguards, FTC Safeguards Rule requirements, and Zero Trust access policies.

But it will not make those decisions for you.

Your firm must choose the right controls, configure them correctly, monitor them continuously, and document how they support your business and regulatory obligations.

If you are unsure where your tenant stands, start with a structured Microsoft 365 security assessment. A PC of Mind helps regulated professional-services organizations assess risk, strengthen identity and devices, protect email and data, and build reliable business continuity.

Explore our cybersecurity services, managed IT services, or contact A PC of Mind to begin.

This article is provided for general informational purposes and does not constitute legal, regulatory, or compliance advice. Consult qualified legal and compliance professionals regarding your specific obligations.

Further reading: