ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Microsoft 365 Security Settings Law Firms Often Leave Off

A review of Microsoft 365 settings that matter for law firms, from MFA and legacy authentication to forwarding rules, sharing and audit logging.

3 min readBy Counsel Cyber Team

Microsoft 365 is the backbone of most law firms: email, calendars, Teams, OneDrive, SharePoint and often the sign-in for other applications. It is also a favorite attack target. The platform has strong security capabilities, but many are not enabled by default or depend on your license level. A tenant set up quickly years ago and never revisited often has gaps that an attacker could use.

This post lists settings worth reviewing with your administrator or IT provider. Names and availability change over time and depend on your license, so treat this as a conversation guide rather than a click-by-click procedure.

Identity and sign-in

Require multi-factor authentication for everyone

Not just attorneys, and not just on most days. Include administrators, shared accounts where possible, service accounts that can be converted and every partner. Prefer app-based or hardware-based methods over text messages when you can.

Block legacy authentication

Older protocols can't prompt for MFA, so attackers use them to bypass it. Confirm they are blocked unless a specific, documented need exists.

Use conditional access

Where your licensing allows, set rules such as requiring MFA from unfamiliar locations, blocking sign-ins from countries where you have no business and requiring compliant, managed devices for sensitive access.

Limit administrator accounts

Keep the number of global administrators small, use separate admin accounts from daily mailboxes and protect them with the strongest MFA available.

Email protections

Forwarding rules

Attackers who compromise a mailbox commonly create hidden rules that forward or delete messages. Restrict automatic external forwarding and periodically audit mailbox rules.

Anti-phishing and safe attachment tools

Check whether advanced protections are licensed and configured, including impersonation protection for your attorneys' names and domains that closely resemble yours.

External sender warnings

A visible "external" tag helps staff spot messages impersonating colleagues.

Email authentication

Make sure SPF, DKIM and DMARC are set up for your domain so others can verify mail claiming to be from you. DMARC in enforcement mode makes it harder to spoof your firm's name.

Data protection

Sharing settings

Review how OneDrive and SharePoint allow external sharing. Anonymous "anyone with the link" sharing is convenient and risky. Prefer named-person sharing with expiration dates for client documents.

Sensitivity labels and data loss prevention

If licensed, labels can mark documents as privileged or confidential and restrict sharing. Data loss prevention rules can warn or block when sensitive patterns, such as Social Security numbers, leave the tenant.

Retention policies

Align retention settings with your records policy and legal hold process. Know who can change them.

Devices and apps

  • Device compliance requirements so unmanaged devices can't sync firm data.
  • Mobile application management to separate firm data on personal phones.
  • Third-party app consent. Restrict users from granting permissions to unknown apps that request access to mail or files. Malicious consent requests are a known technique.

Monitoring and logging

  • Audit logging should be on, and retention should be long enough to investigate. Some log data is kept for a limited period depending on license.
  • Alerts for impossible-travel sign-ins, new forwarding rules, mass downloads and administrator role changes.
  • Secure score or similar dashboards can offer a starting list of recommendations, though not every recommendation fits every firm.

Collaboration

Teams and SharePoint sites can proliferate. Decide who may create teams, how guests are approved and how client matter workspaces are named and archived. Regularly review guest accounts and remove those no longer needed.

Backup

Microsoft operates the service, but retention features are not the same as an independent backup. Decide whether a separate copy of mailboxes and files is appropriate for your firm.

A 30-day review plan

  1. Week one: audit MFA coverage and administrator accounts; block legacy authentication.
  2. Week two: review mailbox forwarding rules and anti-phishing configuration; confirm DMARC status.
  3. Week three: review sharing settings, guest accounts and device compliance.
  4. Week four: confirm logging and alerting, and document the configuration.

How Counsel Cyber can help

Counsel Cyber configures and monitors Microsoft 365 for law firms, including security hardening and licensing review. If you would like a baseline assessment of your tenant, we can walk through it with you.