
Solicitors, accountants, consultants and advisers use Microsoft 365 to send advice, collaborate on documents and keep client relationships moving. That work can involve contracts, financial records, identity documents, commercially sensitive plans and privileged correspondence.
Microsoft 365 includes strong security capabilities, but having the licences is not the same as having a secure environment. The important questions are whether the right controls are enabled, whether they are applied consistently and whether someone is watching for changes and unusual activity.
What should a professional services firm ask first?
Before changing settings, it helps to ask a few straightforward questions:
- Could an attacker use one stolen password to reach email, files and client information?
- Do administrators have more access than they need, and are old accounts still active?
- Can an unmanaged or lost device download company data?
- Can a user accidentally share a sensitive document with the wrong person?
- Would the firm know quickly if a mailbox or account had been compromised?
- Can the team restore important work after deletion, malware or a wider service incident?
1. Protect identities before protecting anything else
Microsoft Entra ID is the identity and access layer behind Microsoft 365. It decides who a user is, which applications they can reach and what conditions must be met before access is allowed. If an attacker takes over a user identity, they may be able to read email, impersonate the user or access SharePoint and OneDrive files without breaking through a traditional office network.
A sensible baseline includes:
- A named account for every person, with no shared logins for fee earners, finance staff or administrators
- Separate administrator accounts so day-to-day email and web browsing do not use elevated privileges
- Security defaults or carefully planned Conditional Access policies, depending on the tenant and licence level
- A documented joiner, mover and leaver process that removes access promptly when circumstances change
- Regular review of guest users, application consent and sign-in activity
Conditional Access is Microsoft's policy engine for making access decisions from signals such as the user, device, location and risk. For example, a policy can require stronger verification or block access when a sign-in does not meet the firm's rules. It should be introduced carefully, with pilot users and emergency access arrangements, so a well-intended policy does not lock out the people responsible for fixing it.
2. Make multi-factor authentication meaningful
Multi-factor authentication (MFA) means a password alone is not enough to sign in. It is one of the most important protections for Microsoft 365, particularly for administrators, people who handle payments and anyone with access to a broad collection of client files.
Good MFA implementation is more than switching on a prompt:
- Register every user and administrator, then remove old or unrecognised authentication methods
- Prefer strong, phishing-resistant methods such as passkeys or security keys where they are practical
- Use number matching and clear sign-in guidance so staff can recognise unexpected prompts
- Keep tightly controlled emergency access accounts for recovery, and alert on their use
- Test the process when someone loses a phone, changes number or is travelling
MFA reduces the value of a stolen password, but it does not stop every attack. A user can still approve a convincing fraudulent request, and a compromised session may still be abused. That is why MFA needs to sit alongside sign-in monitoring, device controls and staff awareness.
3. Give people only the permissions they need
Access should follow the work someone does, not the convenience of giving everyone broad access. A junior team member may need a matter folder or client workspace, while a partner, practice manager or finance lead may need a different set of systems. Those decisions should be visible and reviewable.
- Use role-based groups where possible instead of assigning permissions one person at a time
- Keep Global Administrator and other privileged roles to a small number of named people
- Review Microsoft 365 groups, Teams, shared mailboxes and third-party app access
- Use access reviews for guests and important groups, especially when a project ends
- Remove access that was granted for a temporary matter, transaction or handover
This matters in every professional services firm, but especially where teams work across departments or handle client matters with different confidentiality requirements. A permission review is not a promise that information can never be exposed. It is a practical way to reduce unnecessary access and spot exceptions before they become incidents.
4. Treat email as a security control, not just a mailbox
Email remains a common route into a firm and a common way for criminals to exploit trust. An attacker who gains access to a mailbox can quietly read conversations, create forwarding rules and wait for the right moment to impersonate a partner, solicitor or supplier.
Review the protections available in the firm's Microsoft 365 plan, including:
- Anti-phishing, anti-spam and anti-malware policies, with sensible protection for spoofed domains and impersonated people
- Safe Links and Safe Attachments where the licence supports Microsoft Defender for Office 365
- Alerts for suspicious inbox rules, forwarding and unusual sign-in behaviour
- SPF, DKIM and DMARC for the firm's domains, configured and monitored rather than added once and forgotten
- A clear process for verifying changes to bank details and urgent payment instructions using a trusted channel
A security banner on an external email can be useful, but it is not a substitute for judgement. The most effective process combines technical filtering with training that reflects the firm's real work, such as requests to change client bank details, send a matter file urgently or share a draft transaction document.
5. Control which devices can access client work
A Microsoft 365 account can be secure while the laptop or phone used to access it is not. Lost devices, unpatched operating systems, personal computers and malware can all put client information at risk.
Microsoft Intune can help firms enrol devices, apply configuration policies and report on compliance. Combined with Conditional Access, it can support rules such as requiring an enrolled, healthy device before someone can download company files. A practical device standard normally covers:
- Supported operating systems with security updates installed
- Encryption, screen lock and remote wipe for appropriate devices
- Endpoint protection and a process for responding to alerts
- Separate handling for personal devices, with access limited to what the firm is prepared to manage
- A clear process to remove access when a device is lost, replaced or no longer meets policy
6. Make sharing deliberate
SharePoint, OneDrive, Teams and Microsoft 365 groups make collaboration easy. They can also make it easy to share the wrong file with the wrong person if the firm's defaults are too open or links are never reviewed.
- Prefer links to specific people or named guests over anonymous Anyone links for client work
- Set organisation and site sharing limits that match the firm's risk appetite
- Use expiry dates, view-only access and download restrictions where appropriate
- Use sensitivity labels or data loss prevention features where the licence and workflow support them
- Review guest access and external links when a matter, engagement or project closes
External collaboration is often essential for advisers and client teams, so blocking every form of sharing is rarely practical. The goal is to make the safer option the easiest option, then review exceptions rather than letting them become permanent.
7. Plan recovery before you need it
Version history, recycle bins, retention settings and Microsoft's service resilience can all help recover work, but they are not automatically the same as an independent backup with a tested restore process. A firm should know which information is business-critical, how long it needs to retain it and how quickly it would need to recover it.
A sensible recovery plan includes:
- A documented inventory of important mailboxes, SharePoint sites, OneDrive data and Teams content
- Recovery arrangements that cover accidental deletion, malicious deletion and a wider account or service incident
- Clearly assigned recovery responsibilities and securely controlled administrator access
- Regular restore tests using realistic files and scenarios
- A communication plan for clients, staff, insurers and relevant professional or regulatory bodies where appropriate
Recovery is not only an IT exercise. A solicitor may need to prioritise active matters, an accountant may need access to payroll or reporting records, and an adviser may need to contact clients through a trusted alternative channel. Those priorities should be agreed before an incident.
8. Monitor, review and improve
Security settings drift. People change roles, suppliers are replaced, new applications are connected and a policy that was sensible for a small team can become unsuitable as the firm grows. Ongoing review is what turns a configuration into a security process.
At a minimum, firms should agree who will:
- Review sign-in, audit and security alerts, with an escalation route for suspicious activity
- Check privileged roles, guests, forwarding rules and application permissions
- Track devices that are missing updates or falling out of compliance
- Test joiner, mover and leaver processes
- Review sharing, recovery and incident response controls at an agreed cadence
- Record actions, owners and due dates so recommendations do not disappear after a meeting
Common Microsoft 365 security mistakes
The most common problems are usually not a lack of available features. They are gaps between the feature and the way the firm operates:
- MFA is enabled for most staff but not every administrator, contractor or service account
- A Conditional Access policy is created without testing exclusions, emergency access or line-of-business applications
- Former staff and guests retain access because nobody owns the review
- Sensitive documents are shared through open links because the safer sharing method is unclear
- Email security is left at default settings and no one checks alerts or mailbox rules
- A backup product exists, but no one has tested whether it can restore the data the firm actually needs
- The tenant is configured once and never reviewed after the business, team or threat landscape changes
A practical review process for professional services firms
A useful review does not need to begin with a long technical report. Start by listing the people, information and activities that would cause the greatest harm if disrupted or exposed. Then map the relevant Microsoft 365 controls to those risks, record what is already in place and prioritise the gaps.
- 1Understand the firm's clients, workflows, sensitive data and working locations
- 2Review identities, administrators, MFA, sign-in risk and connected applications
- 3Check permissions, devices, email protection, sharing and recovery
- 4Test the controls with a small group before wider changes are made
- 5Agree owners, priorities and review dates, then report progress in business language
Microsoft 365 can support a strong security approach, but the right design depends on the firm's size, data, workflows, existing systems and licence level. No configuration can remove all risk, and this guide is not a certification or compliance guarantee. It is a starting point for a more deliberate conversation about protecting client information.
How Konnetix helps professional services firms
At Konnetix, we help solicitors, accountants, consultants and advisers bring Microsoft 365 security, device management, support and recovery into one practical plan. Our Complete 365 service for professional services firms is designed around client confidentiality, secure hybrid working and clear ongoing management.
If you are unsure which controls are active, whether your sharing settings are appropriate or how quickly you could recover after an account compromise, an initial review can turn those questions into a prioritised action plan.
Review your Microsoft 365 security
Talk to Konnetix about a practical security review for your professional services firm. We will explain the risks and priorities in plain language, without promising a one-size-fits-all compliance outcome.
Book a Free Security Review