For most small and mid-size firms, Microsoft 365 is the center of operations: email, calendars, OneDrive, SharePoint, Teams and often the sign-in for other tools. That makes its configuration one of the most consequential security decisions a firm makes, and one of the most often left at default settings.
Below is a practical review list. Names and menu locations change over time and depend on your license level, so have your IT administrator confirm each item against your tenant.
Identity and sign-in
- Enforce MFA for every user, with no permanent exceptions. Review any accounts excluded from MFA policies.
- Use conditional access where your licensing allows, to require MFA from unfamiliar locations, block sign-ins from countries where no one at the firm travels, and require compliant devices for sensitive apps.
- Block legacy authentication. Older email protocols cannot prompt for MFA, and attackers use them to bypass it.
- Limit administrator accounts. Use separate admin accounts that are not used for email, and require stronger MFA for them. Keep the number of global administrators small, and maintain emergency access accounts stored securely.
- Review guest accounts. Remove external guests who no longer need access.
Email protection
- Anti-phishing policies: Enable impersonation protection for key people such as partners and the finance team, and for your own domain.
- Safe links and safe attachments, if included in your plan.
- SPF, DKIM and DMARC records for your domain. DMARC set to enforcement helps prevent attackers from sending email that appears to come from your firm.
- External sender banner: Mark messages from outside the organization so that a spoofed "internal" request stands out.
- Auto-forwarding rules: Disable automatic forwarding to external addresses. Attackers who compromise a mailbox commonly create hidden forwarding or inbox rules to watch payment conversations.
- Mailbox rule alerts: Alert on newly created rules that forward or delete mail.
Sharing and data
- External sharing in SharePoint and OneDrive: Restrict to specific people, require sign-in, and set expiration on links. Consider limiting anonymous "anyone" links.
- Sensitivity labels and data loss prevention, if licensed, to flag or block sharing of sensitive content such as Social Security numbers.
- Retention policies: Align with your records retention schedule and any legal holds.
- Teams: Control who can create teams, who can invite guests, and what happens to files shared in chat.
Devices
- Require encryption and screen locks on phones and laptops accessing firm data.
- Use mobile device management or app protection policies so you can remove firm data from a lost device without wiping personal photos.
- Remove old devices from the device list.
Logging and monitoring
- Confirm the unified audit log is enabled, and know how long it is retained at your license level.
- Review sign-in logs for impossible-travel alerts and repeated failures.
- Make sure someone is actually watching alerts. Logs nobody reads do not protect you.
Backup
Microsoft operates the service, but retention and recycle bins are not a full backup. Consider a third-party backup of mailboxes, OneDrive and SharePoint so you can recover from accidental deletion, malicious activity or a compromised account.
Secure score and licensing
Microsoft provides a built-in security score with recommendations. It is a useful starting point, though not every suggestion fits every firm. Also check whether your license tier includes the controls you need. A few additional dollars per user can unlock features that matter.
A simple quarterly routine
- Review administrator and guest accounts
- Check MFA coverage reports
- Review new mail-forwarding rules and external sharing
- Scan alerts and sign-in anomalies
- Verify backups
- Review any licensing changes
If your firm has never reviewed these settings, do not try to change everything in one weekend. Make changes in stages, communicate them to users in advance, and test with a small group first so a new policy does not lock an attorney out the morning of a hearing.
Next step with Counsel Cyber
We audit Microsoft 365 tenants for law firms and implement the changes safely, without disrupting active matters. Ask for a configuration review and we will give you a prioritized list.