Business team defends digital fortress against hackers using shields, firewall, and security tools in a castle moat setting.

How Should a Financial Firm Secure Microsoft 365 Against Phishing, Account Takeover, and Data Loss?

August 07, 2026

Quick Answer: Financial Firms Should Apply a 10-Control Microsoft 365 Security Baseline

A financial firm should secure Microsoft 365 with at least 10 foundational controls: multi-factor authentication, Conditional Access, separate administrator accounts, email threat protection, anti-impersonation controls, device management, secure file-sharing rules, audit logging, tested cloud backups, and a documented employee offboarding process.

For a 25–50 employee financial organization, Microsoft 365 security should be reviewed at least quarterly, while sign-in alerts, email threats, and endpoint activity should be monitored continuously. High-risk accounts, such as executives, finance employees, administrators, and anyone authorized to approve payments, should receive additional protection.

Microsoft 365 includes powerful security capabilities, but those features must be licensed, configured, monitored, and maintained correctly. Financial firms should combine secure cloud management with managed cybersecurity, employee training, backups, and documented response procedures.

The 10-Control Microsoft 365 Security Framework

Control Primary purpose Recommended review
1. Multi-factor authentication Reduce unauthorized access when passwords are stolen Quarterly
2. Conditional Access Control sign-ins based on identity, location, device, and risk Quarterly
3. Separate administrator accounts Reduce exposure of powerful privileges Quarterly
4. Email threat protection Block phishing, malware, dangerous links, and attachments Continuous
5. Anti-impersonation protection Reduce executive, vendor, and payment fraud Monthly
6. Device management Control which devices can access company information Monthly
7. Secure sharing and permissions Limit accidental or unauthorized data exposure Quarterly
8. Audit logging and alerting Detect suspicious activity and support investigations Continuous
9. Independent cloud backups Recover from deletion, ransomware, or account compromise Quarterly restore testing
10. Onboarding and offboarding Grant and remove access consistently Every employee change

1. Enforce Multi-Factor Authentication for Every User

Multi-factor authentication requires a user to provide more than a password before accessing an account. This significantly reduces the likelihood that a stolen password alone will result in unauthorized access.

MFA should be required for:

  • Every employee
  • Executives and owners
  • Microsoft 365 administrators
  • Remote employees
  • Temporary workers and contractors
  • Shared or service accounts whenever supported
  • Third parties with access to company resources

Do not rely on optional enrollment. The requirement should be enforced through Microsoft 365 security policies and reviewed regularly for exemptions, inactive users, and older sign-in methods that could bypass protection.

Use stronger authentication for high-risk accounts

Executives, financial personnel, administrators, and employees who can approve payments or access large amounts of confidential information should receive stronger protection. Depending on the organization’s needs, this may include authenticator applications, hardware security keys, passkeys, device compliance, or additional sign-in restrictions.

Questions to ask your IT provider

  • Is MFA enforced for 100% of active users?
  • Are any accounts exempt?
  • Can older authentication protocols bypass MFA?
  • Which authentication methods are allowed?
  • How are lost devices and MFA resets handled?

2. Use Conditional Access to Control Sign-In Risk

Conditional Access allows an organization to permit, block, or challenge sign-ins according to defined conditions. These policies can help prevent access from risky locations, unmanaged devices, outdated applications, or suspicious sign-in activity.

Common policies for financial firms include:

  • Require MFA for all users
  • Block older authentication protocols
  • Require stronger controls for administrators
  • Restrict access from high-risk countries or locations
  • Require compliant devices for sensitive applications
  • Block sign-ins identified as high risk
  • Require additional verification for unusual activity
  • Limit access from unknown or unmanaged devices

Conditional Access policies should be introduced carefully. A poorly planned policy can block legitimate employees or create an administrator lockout. Test policies with a small group before enforcing them across the organization, and maintain a documented emergency-access procedure.

3. Separate Daily User Accounts From Administrator Accounts

Microsoft 365 administrators can create users, change security settings, reset passwords, access data, and disable protections. These privileges should not be attached to accounts used for daily email and web browsing.

A secure administrative model should include:

  • A normal account for daily work
  • A separate named account for administrative work
  • MFA on every privileged account
  • No shared administrator credentials
  • Only the permissions required for each role
  • Logging of administrator activity
  • Quarterly privilege reviews
  • Immediate removal of unnecessary access

Limit the number of global administrators. Many routine Microsoft 365 tasks can be assigned through narrower roles without granting full control over the tenant.

Maintain emergency access securely

The organization may maintain a tightly controlled emergency account for situations in which normal administrative access is unavailable. This account should be protected, monitored, tested, and used only according to a documented procedure.

4. Strengthen Email Protection Beyond Basic Spam Filtering

Email attacks often attempt to steal passwords, install malware, redirect payments, impersonate executives, or convince employees to disclose sensitive information. Basic spam filtering is not sufficient for a financial firm.

A layered email-security program should include:

  • Phishing protection
  • Malware and attachment scanning
  • Suspicious-link analysis
  • Impersonation detection
  • Spoofing protection
  • External-sender identification
  • Domain-authentication controls
  • Quarantine review procedures
  • A simple phishing-reporting button
  • Security awareness training

Financial firms should also establish procedures for verifying requests involving wire transfers, payroll changes, banking information, passwords, tax documents, or access to client records.

Use an independent verification process

Employees should confirm unusual payment or account-change requests through a known phone number, approved workflow, or separate trusted communication channel. They should not rely on the contact information contained in the suspicious message.

5. Protect Against Executive and Vendor Impersonation

Business email compromise often involves messages that appear to come from an owner, executive, client, vendor, or financial institution. The attacker may request an urgent payment, a change to banking information, confidential tax data, gift cards, or employee credentials.

Anti-impersonation controls should protect:

  • Owners and executives
  • Finance and accounting employees
  • Payroll personnel
  • Human resources staff
  • Frequently impersonated vendors
  • Domains similar to the firm’s domain
  • Client-facing employees

Technical protections should be reinforced by documented approval procedures. For example, a financial firm may require two-person approval and independent verification before banking information or payment instructions are changed.

6. Manage the Devices That Access Microsoft 365

A secure Microsoft 365 environment should consider both the user’s identity and the condition of the device being used. A legitimate employee signing in from an infected, stolen, or unmanaged device can still create risk.

Device controls may include:

  • Device registration and inventory
  • Endpoint detection and response
  • Disk encryption
  • Screen-lock requirements
  • Operating-system updates
  • Mobile-device security policies
  • Remote wipe for company data
  • Restrictions on personal devices
  • Requirements for compliant devices
  • Removal of access from inactive equipment

The firm should decide whether employees may access email and files from personal computers and mobile devices. The policy should explain what security requirements apply and what the organization can remove if a device is lost or the employee leaves.

7. Restrict External File Sharing and Excessive Permissions

Microsoft 365 makes it easy to share files through SharePoint, OneDrive, and Teams. That convenience can lead to accidental data exposure when links are public, permissions never expire, or former vendors retain access.

A secure sharing process should address:

  • Whether anonymous sharing links are allowed
  • Which employees may share files externally
  • How long sharing links remain active
  • Whether recipients must authenticate
  • How guest users are approved
  • How sensitive folders are protected
  • How external access is reviewed
  • How access is removed after a project ends

For confidential financial or client information, require authenticated access and limit sharing to the minimum necessary recipients. Avoid using unrestricted links for documents containing tax records, financial statements, identification information, payroll data, or investment details.

Review permissions quarterly

A quarterly access review should examine:

  • External guests
  • Shared links
  • Former employees
  • Unused groups and Teams
  • Shared mailboxes
  • Executive and finance folders
  • Users with elevated privileges

8. Enable Audit Logging, Monitoring, and Security Alerts

Microsoft 365 produces valuable information about sign-ins, mailbox activity, administrator changes, file sharing, forwarding rules, and other events. That information is useful only when the correct logging is enabled, retained, and reviewed.

Monitoring should look for activity such as:

  • Sign-ins from unusual locations
  • Repeated failed sign-in attempts
  • New mailbox forwarding rules
  • Unexpected administrator-role changes
  • Large file downloads
  • External sharing of sensitive information
  • Security settings being disabled
  • New applications receiving account access
  • Suspicious inbox rules
  • Unusual email-sending activity

High-risk alerts should have a defined response process. The organization and its provider should know who investigates, who contacts the employee, when an account is disabled, and how evidence is preserved.

911 IT integrates Microsoft 365 oversight with broader cybersecurity monitoring and incident response.

9. Back Up Microsoft 365 Data Independently

Microsoft 365 provides availability and retention capabilities, but firms should not assume every deleted, encrypted, overwritten, or compromised item can be recovered indefinitely.

An independent Microsoft 365 backup can help recover:

  • Exchange Online email
  • OneDrive files
  • SharePoint data
  • Teams-related files
  • Deleted user information
  • Files altered by ransomware
  • Items removed beyond the available retention period

The backup agreement should define:

  • Which Microsoft 365 services are protected
  • How often backups run
  • How long data is retained
  • Whether data is encrypted
  • Who can perform a restore
  • How departing-user data is preserved
  • How frequently recovery is tested
  • What happens when the backup service ends

Conduct a documented restore test at least quarterly for critical Microsoft 365 data. Review 911 IT’s business continuity services for additional information about backup and recovery planning.

10. Standardize Employee Onboarding and Offboarding

Employee changes are a common source of access errors. A documented checklist helps ensure that each person receives the correct permissions when hired and loses access promptly when departing.

A secure onboarding checklist should include

  • Create a named user account
  • Assign only required licenses
  • Enroll MFA
  • Configure the company device
  • Apply security policies
  • Grant access according to job duties
  • Provide security awareness training
  • Document equipment and application assignments

A secure offboarding checklist should include

  • Disable sign-in promptly
  • Revoke active sessions
  • Remove administrator privileges
  • Reset or remove authentication methods
  • Preserve email and files according to policy
  • Remove access from mobile and personal devices
  • Transfer necessary business data
  • Review shared credentials and applications
  • Remove the user from groups and Teams
  • Document completion

Managers should notify IT before the employee’s departure whenever possible. For urgent or involuntary terminations, the organization should coordinate the timing carefully so access can be disabled at the correct moment.

How Microsoft 365 Account Takeovers Usually Happen

Account compromise often begins with one of five events:

  1. Phishing: The employee enters a password into a fake sign-in page.
  2. Password reuse: A password exposed elsewhere is used against Microsoft 365.
  3. MFA fatigue: The employee approves an unexpected authentication request.
  4. Malicious application consent: The user grants an application permission to access email or files.
  5. Session theft: An attacker steals an active browser session or authentication token.

Once inside the account, an attacker may read email, create forwarding rules, search for invoices, impersonate the employee, request payments, access files, or use the account to target coworkers and clients.

Signs That a Microsoft 365 Account May Be Compromised

  • Unexpected MFA prompts
  • Sign-ins from unfamiliar locations or devices
  • Messages appearing in the sent folder that the user did not send
  • Emails being moved, deleted, or marked as read unexpectedly
  • New forwarding or inbox rules
  • Clients reporting suspicious messages
  • Password or security settings changing without authorization
  • Files being downloaded or shared unexpectedly
  • The employee being locked out of the account
  • Unusual requests involving payments or sensitive information

Employees should know how to report suspicious activity immediately. Delayed reporting can give an attacker more time to access data, impersonate the firm, and target clients.

What Should Happen After an Account Compromise?

A documented response should address at least seven actions:

  1. Disable or restrict the account: Stop unauthorized access while the event is investigated.
  2. Revoke active sessions: Prevent an attacker from continuing to use an existing session.
  3. Reset credentials and authentication methods: Replace passwords and review MFA registrations.
  4. Review administrator roles and application access: Remove unauthorized permissions or connected applications.
  5. Inspect forwarding and inbox rules: Delete malicious rules and confirm message handling.
  6. Investigate activity: Review sign-ins, email, file access, sharing, and other relevant logs.
  7. Determine notification and recovery steps: Coordinate with leadership, legal counsel, insurers, compliance professionals, clients, and other parties as appropriate.

The organization should preserve relevant logs and document actions taken. Do not delete evidence before qualified personnel determine what may be needed for an investigation, insurance claim, legal review, or regulatory response.

A 90-Day Microsoft 365 Security Improvement Plan

Days 1–30: Assess

  • Inventory all users, administrators, guests, and licenses
  • Measure MFA coverage
  • Review older authentication methods
  • Identify unused and former-employee accounts
  • Review email-security settings
  • Examine external file sharing
  • Confirm audit logging and alerting
  • Review backup coverage

Days 31–60: Correct High-Risk Gaps

  • Enforce MFA
  • Create separate administrator accounts
  • Block older authentication
  • Implement baseline Conditional Access policies
  • Strengthen phishing and impersonation protection
  • Remove unused accounts and permissions
  • Secure external sharing
  • Deploy or validate Microsoft 365 backups

Days 61–90: Test and Document

  • Run a phishing simulation
  • Test a Microsoft 365 data restore
  • Conduct an account-compromise tabletop exercise
  • Document onboarding and offboarding
  • Review administrator activity
  • Establish quarterly access reviews
  • Present security metrics and remaining risks to leadership

Seven Microsoft 365 Metrics Leadership Should Review

Metric Suggested objective
MFA coverage 100% of active users
Privileged-account review Completed quarterly
Inactive accounts Investigated and removed promptly
High-risk sign-ins Investigated according to a documented process
External guests and sharing links Reviewed quarterly
Microsoft 365 backup testing Successful documented restore tests
Security training 100% employee completion

Microsoft 365 Security Licensing Questions to Ask

Security capabilities vary by Microsoft 365 license and configuration. Ask your IT provider:

  1. Which Microsoft 365 licenses do we currently use?
  2. Which security features are included in those licenses?
  3. Which recommended protections require an upgrade?
  4. Do we have more licenses than active users?
  5. Are former employees still consuming licenses?
  6. Are security features enabled, or merely available?
  7. Are third-party security tools duplicating Microsoft capabilities?
  8. Which licenses are included in our managed IT agreement?
  9. How often is licensing reviewed?
  10. Can we reduce cost without weakening security?

The least expensive license is not always the lowest-cost option when it requires multiple add-ons or leaves important safeguards unavailable. Compare the total cost of the security stack rather than the license price alone.

Common Microsoft 365 Security Mistakes

  • MFA is enabled but not enforced. Users can postpone or avoid enrollment.
  • Administrators use privileged accounts for daily work. Phishing or malware can expose powerful access.
  • Older authentication remains available. Attackers may use protocols that do not support modern protections.
  • External sharing is unrestricted. Sensitive information can remain accessible long after the business need ends.
  • Former employees retain access. Incomplete offboarding leaves email, files, applications, or sessions active.
  • Email security relies on default filtering. Advanced phishing and impersonation attacks may require additional controls.
  • No one reviews alerts after hours. Suspicious activity can continue overnight or through a weekend.
  • Microsoft 365 is not backed up independently. The firm may have limited recovery options after deletion or compromise.
  • Licenses are purchased but features are not configured. Available security capabilities provide no value until implemented.
  • Access reviews are never completed. Guests, applications, administrators, and shared links accumulate over time.

A Practical Example: Preventing Payment Fraud

Consider a 35-employee financial firm whose controller receives an email that appears to come from the owner. The message requests an urgent payment to a new bank account and explains that the owner is unavailable by phone.

A weak environment may allow the message to reach the inbox without warning, and the employee may process the payment based on the apparent sender.

A stronger environment uses multiple controls:

  • Anti-impersonation protection flags the message
  • An external-sender notice warns the employee
  • Security awareness training helps the employee recognize urgency and secrecy as warning signs
  • A written payment procedure requires independent verification
  • Two-person approval prevents one employee from completing the transaction alone
  • The employee reports the email for investigation

No single control eliminates the risk. The combination of technology, training, and business procedures creates stronger protection.

What Financial Clients Say About 911 IT

“It’s clear they understand our industry and the security standards required to keep client data safe.”

Lee, Owner, Financial Industry

“If you’re serious about protecting client data and want a reliable IT partner who truly understands compliance, 911 IT is the way to go.”

Kari, Accountant, Financial Industry

Financial-industry clients also describe 911 IT as proactive, responsive, accessible, and knowledgeable. They highlight the value of having a team that understands financial applications, secures remote access, protects client information, and follows through until support issues are resolved.

How 911 IT Helps Secure Microsoft 365

911 IT helps financial organizations manage and protect Microsoft 365 through:

  • Microsoft 365 licensing and administration
  • Multi-factor authentication
  • Identity and access management
  • Email security and phishing prevention
  • Cloud file-sharing controls
  • User onboarding and offboarding
  • Endpoint and device security
  • 24/7 threat monitoring
  • Microsoft 365 backup and recovery
  • Security awareness training
  • Incident-response support
  • Quarterly technology and security reviews

Learn more about 911 IT’s cloud services, cybersecurity services, and specialized IT support for financial firms.

Take One Action This Week

Ask your IT provider for a Microsoft 365 security report that answers five questions:

  1. What percentage of active users have enforced MFA?
  2. How many administrator accounts exist?
  3. How many inactive, guest, or former-employee accounts remain?
  4. When was Microsoft 365 data last restored from backup?
  5. Who reviews high-risk sign-in and email-security alerts after hours?

If the answers are unavailable, incomplete, or based on assumptions, schedule a formal Microsoft 365 security review.

Schedule a Microsoft 365 Security Assessment

A Microsoft 365 security assessment should identify risky sign-in settings, weak administrator practices, email vulnerabilities, excessive sharing, inactive accounts, missing backups, and monitoring gaps. The result should be a prioritized improvement plan rather than a generic list of product recommendations.

Schedule a discovery call with 911 IT to review your Microsoft 365 licenses, users, administrators, email security, file-sharing practices, backups, and compliance concerns.