ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Microsoft 365 Settings Law Firms Often Leave Unconfigured

Microsoft 365 ships with convenient defaults that are not always safe for law firms. Review these settings for email, sharing, identity and retention.

3 min readBy Counsel Cyber Team

Microsoft 365 is the backbone of most law firms: email, calendars, Word, Teams, SharePoint and OneDrive. It is also configurable in hundreds of ways, and the default settings are tuned for convenience across millions of customers, not for the confidentiality needs of a law firm. A few hours of configuration review can close real gaps.

Menu names and licensing features change over time, and some controls depend on your subscription tier, so work with your IT provider to confirm what applies to you.

Identity and sign-in

Enforce multi-factor authentication

Require MFA for all users, including administrators and shared mailboxes where possible. Use conditional access policies, or the platform's security defaults if you have no better option, so MFA is enforced consistently rather than left to individual choice.

Block legacy authentication

Older protocols cannot use MFA, and attackers probe for them. Disable them unless a specific, documented need exists.

Limit administrator roles

Assign administrator rights narrowly, use separate admin accounts without mailboxes and protect them with the strongest methods available.

Add sign-in risk controls

If your license includes them, enable policies that challenge or block risky sign-ins, such as unfamiliar locations.

Email protection

  • Anti-phishing and safe links and attachments. Confirm the protections are active and include impersonation protection for your partners' names.
  • External sender tagging. Mark outside email visibly.
  • Auto-forwarding to external addresses. Block it by default, because attackers use it to siphon mail.
  • SPF, DKIM and DMARC. Publish these records for your domain and move DMARC toward an enforcing policy over time, so others cannot easily spoof you.
  • Audit mailbox activity. Make sure mailbox auditing is enabled so you can investigate.

Sharing and collaboration

SharePoint and OneDrive

Review default sharing settings. "Anyone with the link" sharing is convenient but risky for client documents. Consider restricting to specific people or requiring expiration dates and passwords for external links.

Teams

Decide who can create teams, invite guests and share externally. Review guest accounts regularly and remove those no longer needed.

Sensitivity labels

Where licensing allows, labels such as Client Confidential can apply encryption and sharing restrictions automatically. Even simple labeling supports the idea in ABA Formal Opinion 477R of labeling confidential information.

Data protection and retention

  • Retention policies. Set retention for mail and files to match firm policy and legal requirements. Confirm requirements with your state bar and counsel.
  • Litigation hold capability. Know how to place a mailbox or site on hold, and who is authorized.
  • Deleted item recovery. Understand retention windows. Consider independent backup for mail, SharePoint and OneDrive.
  • Data loss prevention. Where available, configure rules to flag or block sharing of patterns such as Social Security numbers.

Devices and mobile access

  • Require device compliance or app protection for access to firm data from phones.
  • Enforce screen locks and encryption.
  • Enable remote wipe for lost devices, scoped to firm data on personal devices.
  • Block access from unmanaged devices to the most sensitive repositories where practical.

Monitoring and alerts

Turn on alerts for administrator changes, new forwarding rules, mass downloads and suspicious sign-ins. Have someone responsible for reviewing them. Review the Secure Score or equivalent tool as a rough guide, understanding that it measures configuration rather than total security.

Licenses and apps

Audit installed apps and third-party consent grants. Remove unused ones. Restrict user consent so employees cannot grant broad access to unknown applications without approval.

Document your configuration

Keep a record of the settings you chose and why. When you change IT providers or a client sends a security questionnaire, that record saves days.

Why this matters

ABA Model Rule 1.1 Comment 8 asks lawyers to understand technology risks, and Model Rule 1.6(c) addresses reasonable efforts to protect client information. Your Microsoft 365 tenant is the place where most client information lives.

How we help

Counsel Cyber reviews and hardens Microsoft 365 for law firms, from identity settings to retention. We can run a configuration review and give you a prioritized list of fixes in plain language.