Quick Answer: Financial Firms Should Apply a 10-Control Microsoft 365 Security Baseline
A financial firm should secure Microsoft 365 with at least 10 foundational controls: multi-factor authentication, Conditional Access, separate administrator accounts, email threat protection, anti-impersonation controls, device management, secure file-sharing rules, audit logging, tested cloud backups, and a documented employee offboarding process.
For a 25–50 employee financial organization, Microsoft 365 security should be reviewed at least quarterly, while sign-in alerts, email threats, and endpoint activity should be monitored continuously. High-risk accounts, such as executives, finance employees, administrators, and anyone authorized to approve payments, should receive additional protection.
Microsoft 365 includes powerful security capabilities, but those features must be licensed, configured, monitored, and maintained correctly. Financial firms should combine secure cloud management with managed cybersecurity, employee training, backups, and documented response procedures.
The 10-Control Microsoft 365 Security Framework
| Control | Primary purpose | Recommended review |
|---|---|---|
| 1. Multi-factor authentication | Reduce unauthorized access when passwords are stolen | Quarterly |
| 2. Conditional Access | Control sign-ins based on identity, location, device, and risk | Quarterly |
| 3. Separate administrator accounts | Reduce exposure of powerful privileges | Quarterly |
| 4. Email threat protection | Block phishing, malware, dangerous links, and attachments | Continuous |
| 5. Anti-impersonation protection | Reduce executive, vendor, and payment fraud | Monthly |
| 6. Device management | Control which devices can access company information | Monthly |
| 7. Secure sharing and permissions | Limit accidental or unauthorized data exposure | Quarterly |
| 8. Audit logging and alerting | Detect suspicious activity and support investigations | Continuous |
| 9. Independent cloud backups | Recover from deletion, ransomware, or account compromise | Quarterly restore testing |
| 10. Onboarding and offboarding | Grant and remove access consistently | Every employee change |
1. Enforce Multi-Factor Authentication for Every User
Multi-factor authentication requires a user to provide more than a password before accessing an account. This significantly reduces the likelihood that a stolen password alone will result in unauthorized access.
MFA should be required for:
- Every employee
- Executives and owners
- Microsoft 365 administrators
- Remote employees
- Temporary workers and contractors
- Shared or service accounts whenever supported
- Third parties with access to company resources
Do not rely on optional enrollment. The requirement should be enforced through Microsoft 365 security policies and reviewed regularly for exemptions, inactive users, and older sign-in methods that could bypass protection.
Use stronger authentication for high-risk accounts
Executives, financial personnel, administrators, and employees who can approve payments or access large amounts of confidential information should receive stronger protection. Depending on the organization’s needs, this may include authenticator applications, hardware security keys, passkeys, device compliance, or additional sign-in restrictions.
Questions to ask your IT provider
- Is MFA enforced for 100% of active users?
- Are any accounts exempt?
- Can older authentication protocols bypass MFA?
- Which authentication methods are allowed?
- How are lost devices and MFA resets handled?
2. Use Conditional Access to Control Sign-In Risk
Conditional Access allows an organization to permit, block, or challenge sign-ins according to defined conditions. These policies can help prevent access from risky locations, unmanaged devices, outdated applications, or suspicious sign-in activity.
Common policies for financial firms include:
- Require MFA for all users
- Block older authentication protocols
- Require stronger controls for administrators
- Restrict access from high-risk countries or locations
- Require compliant devices for sensitive applications
- Block sign-ins identified as high risk
- Require additional verification for unusual activity
- Limit access from unknown or unmanaged devices
Conditional Access policies should be introduced carefully. A poorly planned policy can block legitimate employees or create an administrator lockout. Test policies with a small group before enforcing them across the organization, and maintain a documented emergency-access procedure.
3. Separate Daily User Accounts From Administrator Accounts
Microsoft 365 administrators can create users, change security settings, reset passwords, access data, and disable protections. These privileges should not be attached to accounts used for daily email and web browsing.
A secure administrative model should include:
- A normal account for daily work
- A separate named account for administrative work
- MFA on every privileged account
- No shared administrator credentials
- Only the permissions required for each role
- Logging of administrator activity
- Quarterly privilege reviews
- Immediate removal of unnecessary access
Limit the number of global administrators. Many routine Microsoft 365 tasks can be assigned through narrower roles without granting full control over the tenant.
Maintain emergency access securely
The organization may maintain a tightly controlled emergency account for situations in which normal administrative access is unavailable. This account should be protected, monitored, tested, and used only according to a documented procedure.
4. Strengthen Email Protection Beyond Basic Spam Filtering
Email attacks often attempt to steal passwords, install malware, redirect payments, impersonate executives, or convince employees to disclose sensitive information. Basic spam filtering is not sufficient for a financial firm.
A layered email-security program should include:
- Phishing protection
- Malware and attachment scanning
- Suspicious-link analysis
- Impersonation detection
- Spoofing protection
- External-sender identification
- Domain-authentication controls
- Quarantine review procedures
- A simple phishing-reporting button
- Security awareness training
Financial firms should also establish procedures for verifying requests involving wire transfers, payroll changes, banking information, passwords, tax documents, or access to client records.
Use an independent verification process
Employees should confirm unusual payment or account-change requests through a known phone number, approved workflow, or separate trusted communication channel. They should not rely on the contact information contained in the suspicious message.
5. Protect Against Executive and Vendor Impersonation
Business email compromise often involves messages that appear to come from an owner, executive, client, vendor, or financial institution. The attacker may request an urgent payment, a change to banking information, confidential tax data, gift cards, or employee credentials.
Anti-impersonation controls should protect:
- Owners and executives
- Finance and accounting employees
- Payroll personnel
- Human resources staff
- Frequently impersonated vendors
- Domains similar to the firm’s domain
- Client-facing employees
Technical protections should be reinforced by documented approval procedures. For example, a financial firm may require two-person approval and independent verification before banking information or payment instructions are changed.
6. Manage the Devices That Access Microsoft 365
A secure Microsoft 365 environment should consider both the user’s identity and the condition of the device being used. A legitimate employee signing in from an infected, stolen, or unmanaged device can still create risk.
Device controls may include:
- Device registration and inventory
- Endpoint detection and response
- Disk encryption
- Screen-lock requirements
- Operating-system updates
- Mobile-device security policies
- Remote wipe for company data
- Restrictions on personal devices
- Requirements for compliant devices
- Removal of access from inactive equipment
The firm should decide whether employees may access email and files from personal computers and mobile devices. The policy should explain what security requirements apply and what the organization can remove if a device is lost or the employee leaves.
7. Restrict External File Sharing and Excessive Permissions
Microsoft 365 makes it easy to share files through SharePoint, OneDrive, and Teams. That convenience can lead to accidental data exposure when links are public, permissions never expire, or former vendors retain access.
A secure sharing process should address:
- Whether anonymous sharing links are allowed
- Which employees may share files externally
- How long sharing links remain active
- Whether recipients must authenticate
- How guest users are approved
- How sensitive folders are protected
- How external access is reviewed
- How access is removed after a project ends
For confidential financial or client information, require authenticated access and limit sharing to the minimum necessary recipients. Avoid using unrestricted links for documents containing tax records, financial statements, identification information, payroll data, or investment details.
Review permissions quarterly
A quarterly access review should examine:
- External guests
- Shared links
- Former employees
- Unused groups and Teams
- Shared mailboxes
- Executive and finance folders
- Users with elevated privileges
8. Enable Audit Logging, Monitoring, and Security Alerts
Microsoft 365 produces valuable information about sign-ins, mailbox activity, administrator changes, file sharing, forwarding rules, and other events. That information is useful only when the correct logging is enabled, retained, and reviewed.
Monitoring should look for activity such as:
- Sign-ins from unusual locations
- Repeated failed sign-in attempts
- New mailbox forwarding rules
- Unexpected administrator-role changes
- Large file downloads
- External sharing of sensitive information
- Security settings being disabled
- New applications receiving account access
- Suspicious inbox rules
- Unusual email-sending activity
High-risk alerts should have a defined response process. The organization and its provider should know who investigates, who contacts the employee, when an account is disabled, and how evidence is preserved.
911 IT integrates Microsoft 365 oversight with broader cybersecurity monitoring and incident response.
9. Back Up Microsoft 365 Data Independently
Microsoft 365 provides availability and retention capabilities, but firms should not assume every deleted, encrypted, overwritten, or compromised item can be recovered indefinitely.
An independent Microsoft 365 backup can help recover:
- Exchange Online email
- OneDrive files
- SharePoint data
- Teams-related files
- Deleted user information
- Files altered by ransomware
- Items removed beyond the available retention period
The backup agreement should define:
- Which Microsoft 365 services are protected
- How often backups run
- How long data is retained
- Whether data is encrypted
- Who can perform a restore
- How departing-user data is preserved
- How frequently recovery is tested
- What happens when the backup service ends
Conduct a documented restore test at least quarterly for critical Microsoft 365 data. Review 911 IT’s business continuity services for additional information about backup and recovery planning.
10. Standardize Employee Onboarding and Offboarding
Employee changes are a common source of access errors. A documented checklist helps ensure that each person receives the correct permissions when hired and loses access promptly when departing.
A secure onboarding checklist should include
- Create a named user account
- Assign only required licenses
- Enroll MFA
- Configure the company device
- Apply security policies
- Grant access according to job duties
- Provide security awareness training
- Document equipment and application assignments
A secure offboarding checklist should include
- Disable sign-in promptly
- Revoke active sessions
- Remove administrator privileges
- Reset or remove authentication methods
- Preserve email and files according to policy
- Remove access from mobile and personal devices
- Transfer necessary business data
- Review shared credentials and applications
- Remove the user from groups and Teams
- Document completion
Managers should notify IT before the employee’s departure whenever possible. For urgent or involuntary terminations, the organization should coordinate the timing carefully so access can be disabled at the correct moment.
How Microsoft 365 Account Takeovers Usually Happen
Account compromise often begins with one of five events:
- Phishing: The employee enters a password into a fake sign-in page.
- Password reuse: A password exposed elsewhere is used against Microsoft 365.
- MFA fatigue: The employee approves an unexpected authentication request.
- Malicious application consent: The user grants an application permission to access email or files.
- Session theft: An attacker steals an active browser session or authentication token.
Once inside the account, an attacker may read email, create forwarding rules, search for invoices, impersonate the employee, request payments, access files, or use the account to target coworkers and clients.
Signs That a Microsoft 365 Account May Be Compromised
- Unexpected MFA prompts
- Sign-ins from unfamiliar locations or devices
- Messages appearing in the sent folder that the user did not send
- Emails being moved, deleted, or marked as read unexpectedly
- New forwarding or inbox rules
- Clients reporting suspicious messages
- Password or security settings changing without authorization
- Files being downloaded or shared unexpectedly
- The employee being locked out of the account
- Unusual requests involving payments or sensitive information
Employees should know how to report suspicious activity immediately. Delayed reporting can give an attacker more time to access data, impersonate the firm, and target clients.
What Should Happen After an Account Compromise?
A documented response should address at least seven actions:
- Disable or restrict the account: Stop unauthorized access while the event is investigated.
- Revoke active sessions: Prevent an attacker from continuing to use an existing session.
- Reset credentials and authentication methods: Replace passwords and review MFA registrations.
- Review administrator roles and application access: Remove unauthorized permissions or connected applications.
- Inspect forwarding and inbox rules: Delete malicious rules and confirm message handling.
- Investigate activity: Review sign-ins, email, file access, sharing, and other relevant logs.
- Determine notification and recovery steps: Coordinate with leadership, legal counsel, insurers, compliance professionals, clients, and other parties as appropriate.
The organization should preserve relevant logs and document actions taken. Do not delete evidence before qualified personnel determine what may be needed for an investigation, insurance claim, legal review, or regulatory response.
A 90-Day Microsoft 365 Security Improvement Plan
Days 1–30: Assess
- Inventory all users, administrators, guests, and licenses
- Measure MFA coverage
- Review older authentication methods
- Identify unused and former-employee accounts
- Review email-security settings
- Examine external file sharing
- Confirm audit logging and alerting
- Review backup coverage
Days 31–60: Correct High-Risk Gaps
- Enforce MFA
- Create separate administrator accounts
- Block older authentication
- Implement baseline Conditional Access policies
- Strengthen phishing and impersonation protection
- Remove unused accounts and permissions
- Secure external sharing
- Deploy or validate Microsoft 365 backups
Days 61–90: Test and Document
- Run a phishing simulation
- Test a Microsoft 365 data restore
- Conduct an account-compromise tabletop exercise
- Document onboarding and offboarding
- Review administrator activity
- Establish quarterly access reviews
- Present security metrics and remaining risks to leadership
Seven Microsoft 365 Metrics Leadership Should Review
| Metric | Suggested objective |
|---|---|
| MFA coverage | 100% of active users |
| Privileged-account review | Completed quarterly |
| Inactive accounts | Investigated and removed promptly |
| High-risk sign-ins | Investigated according to a documented process |
| External guests and sharing links | Reviewed quarterly |
| Microsoft 365 backup testing | Successful documented restore tests |
| Security training | 100% employee completion |
Microsoft 365 Security Licensing Questions to Ask
Security capabilities vary by Microsoft 365 license and configuration. Ask your IT provider:
- Which Microsoft 365 licenses do we currently use?
- Which security features are included in those licenses?
- Which recommended protections require an upgrade?
- Do we have more licenses than active users?
- Are former employees still consuming licenses?
- Are security features enabled, or merely available?
- Are third-party security tools duplicating Microsoft capabilities?
- Which licenses are included in our managed IT agreement?
- How often is licensing reviewed?
- Can we reduce cost without weakening security?
The least expensive license is not always the lowest-cost option when it requires multiple add-ons or leaves important safeguards unavailable. Compare the total cost of the security stack rather than the license price alone.
Common Microsoft 365 Security Mistakes
- MFA is enabled but not enforced. Users can postpone or avoid enrollment.
- Administrators use privileged accounts for daily work. Phishing or malware can expose powerful access.
- Older authentication remains available. Attackers may use protocols that do not support modern protections.
- External sharing is unrestricted. Sensitive information can remain accessible long after the business need ends.
- Former employees retain access. Incomplete offboarding leaves email, files, applications, or sessions active.
- Email security relies on default filtering. Advanced phishing and impersonation attacks may require additional controls.
- No one reviews alerts after hours. Suspicious activity can continue overnight or through a weekend.
- Microsoft 365 is not backed up independently. The firm may have limited recovery options after deletion or compromise.
- Licenses are purchased but features are not configured. Available security capabilities provide no value until implemented.
- Access reviews are never completed. Guests, applications, administrators, and shared links accumulate over time.
A Practical Example: Preventing Payment Fraud
Consider a 35-employee financial firm whose controller receives an email that appears to come from the owner. The message requests an urgent payment to a new bank account and explains that the owner is unavailable by phone.
A weak environment may allow the message to reach the inbox without warning, and the employee may process the payment based on the apparent sender.
A stronger environment uses multiple controls:
- Anti-impersonation protection flags the message
- An external-sender notice warns the employee
- Security awareness training helps the employee recognize urgency and secrecy as warning signs
- A written payment procedure requires independent verification
- Two-person approval prevents one employee from completing the transaction alone
- The employee reports the email for investigation
No single control eliminates the risk. The combination of technology, training, and business procedures creates stronger protection.
What Financial Clients Say About 911 IT
“It’s clear they understand our industry and the security standards required to keep client data safe.”
“If you’re serious about protecting client data and want a reliable IT partner who truly understands compliance, 911 IT is the way to go.”
Financial-industry clients also describe 911 IT as proactive, responsive, accessible, and knowledgeable. They highlight the value of having a team that understands financial applications, secures remote access, protects client information, and follows through until support issues are resolved.
How 911 IT Helps Secure Microsoft 365
911 IT helps financial organizations manage and protect Microsoft 365 through:
- Microsoft 365 licensing and administration
- Multi-factor authentication
- Identity and access management
- Email security and phishing prevention
- Cloud file-sharing controls
- User onboarding and offboarding
- Endpoint and device security
- 24/7 threat monitoring
- Microsoft 365 backup and recovery
- Security awareness training
- Incident-response support
- Quarterly technology and security reviews
Learn more about 911 IT’s cloud services, cybersecurity services, and specialized IT support for financial firms.
Take One Action This Week
Ask your IT provider for a Microsoft 365 security report that answers five questions:
- What percentage of active users have enforced MFA?
- How many administrator accounts exist?
- How many inactive, guest, or former-employee accounts remain?
- When was Microsoft 365 data last restored from backup?
- Who reviews high-risk sign-in and email-security alerts after hours?
If the answers are unavailable, incomplete, or based on assumptions, schedule a formal Microsoft 365 security review.
Schedule a Microsoft 365 Security Assessment
A Microsoft 365 security assessment should identify risky sign-in settings, weak administrator practices, email vulnerabilities, excessive sharing, inactive accounts, missing backups, and monitoring gaps. The result should be a prioritized improvement plan rather than a generic list of product recommendations.
Schedule a discovery call with 911 IT to review your Microsoft 365 licenses, users, administrators, email security, file-sharing practices, backups, and compliance concerns.
