ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ten Microsoft 365 Security Settings Every Law Firm Should Check

Microsoft 365 runs email and documents for most firms, yet many tenants ship with weak defaults. Review these ten settings with your IT provider this month.

3 min readBy Counsel Cyber Team

For most law firms, Microsoft 365 is where client communications and documents live. It is also where many attacks land, since a stolen email login gives an attacker a view into matters, contacts and payment conversations. Microsoft provides strong security features, but not all are enabled by default or included in every license tier, and a tenant configured years ago may not reflect current best practice.

This list gives administrators ten settings to review with their IT provider. Names and menu locations change over time, and some features depend on your license, so use this as a conversation guide rather than a click-by-click manual.

1. Multi-Factor Authentication for Every User

Confirm that MFA is enforced, not merely available, for all accounts including partners, shared mailboxes with sign-in and service accounts. Prefer app-based or phishing-resistant methods over text messages when possible.

2. Block Legacy Authentication

Older protocols that cannot perform MFA are a favorite route for attackers. Use conditional access or security defaults to block them, after confirming that no legitimate older device depends on them.

3. Conditional Access Policies

Conditional access lets you set rules on who can sign in from where. Common examples: require MFA, block sign-ins from countries where you have no staff, and require a compliant or managed device for sensitive applications.

4. Limit Administrator Accounts

Keep the number of global administrators small, use separate accounts for administration and daily work, and protect them with the strongest authentication available. Review the list quarterly.

5. Email Authentication Records

SPF, DKIM and DMARC are records that help receiving servers verify that messages claiming to be from your domain really are. A properly enforced DMARC policy makes it harder for criminals to spoof your firm's address in wire-fraud attempts.

6. Anti-Phishing and Safe Links Protection

Check that your tenant has impersonation protection for key people, such as managing partners, and that links and attachments are scanned. Higher license tiers offer more features, so ask what you are entitled to.

7. External Sender Tagging

A visible banner on messages from outside the firm helps staff spot spoofed internal addresses. It is simple and cheap and works best when people are trained to notice it.

8. Mailbox Auditing and Forwarding Rules

Attackers often create hidden inbox rules or external forwarding to monitor conversations. Disable automatic external forwarding unless there is a documented need, and alert on newly created rules. Confirm audit logging is on and retained long enough to support an investigation.

9. Sharing Settings in SharePoint, OneDrive and Teams

Review who can share files externally and whether links can be shared with "anyone." For legal work, restrict anonymous links, require sign-in or expiring access for external sharing, and review guest accounts periodically. Ethical walls should be reflected in permissions.

10. Third-Party App Consent

Users can sometimes grant outside applications access to their mailbox or files with a single click. Restrict user consent so that new apps require administrator approval, and review existing connected apps. Malicious consent requests are an increasingly common attack that bypasses passwords entirely.

How to Review These Settings

  1. Ask your IT provider for a current-state report on each item, with evidence.
  2. Prioritize the gaps, starting with MFA, legacy authentication and forwarding rules.
  3. Test changes with a pilot group before applying them to everyone.
  4. Communicate changes to staff in advance, since stricter rules can surprise people.
  5. Re-check after license changes or major updates.

Microsoft's Secure Score and similar tools can help you track progress, though a high score is not a guarantee of safety.

Why It Matters Professionally

ABA Model Rule 1.6(c) and Formal Opinion 477R address reasonable efforts to protect client communications, and a well-configured tenant is among the most concrete things a firm can do. Confirm local expectations with your state bar.

Do Not Stop at Configuration

Settings drift. People are added, exceptions are granted and licenses change. Pair configuration with ongoing monitoring of sign-in activity, and with training so people know what to report.

How Counsel Cyber Helps

Counsel Cyber specializes in Microsoft 365 security for law firms. If you would like a tenant review that checks these ten areas and more, we can provide a clear written summary with prioritized fixes.