Person building a protective firewall with Microsoft shield blocking hackers and a surveillance drone in an office.

How Should an Engineering Firm Secure Microsoft 365, Email, and Teams?

July 26, 2026

A Seven-Layer Microsoft 365 Security Framework for Engineering Firms

An engineering firm should protect Microsoft 365 with at least seven coordinated security layers: multi-factor authentication, identity-risk monitoring, email filtering, restricted administrative access, managed devices, controlled file sharing, and independent backup.

For a firm with 25 to 50 employees, a practical Microsoft 365 security rollout often takes 30 to 90 days. Security licensing, management, monitoring, training, and backup may add approximately $15 to $75 per user per month, depending on the Microsoft plan, existing tools, compliance requirements, and level of 24/7 monitoring.

Microsoft provides a resilient cloud platform, but the engineering firm remains responsible for account security, permissions, device access, data sharing, retention, employee behavior, and recovery. A basic password and default Microsoft 365 configuration are not enough to protect project drawings, client correspondence, contracts, intellectual property, and regulated information.

This guide presents a seven-layer framework for securing Exchange Online, Microsoft Teams, SharePoint, OneDrive, and the identities employees use to access them.

The Seven-Layer Microsoft 365 Security Framework

  1. Require strong multi-factor authentication.
  2. Control administrator accounts and privileges.
  3. Detect risky sign-ins and account compromise.
  4. Strengthen email and phishing defenses.
  5. Manage every device that accesses company information.
  6. Control Teams, SharePoint, OneDrive, and external sharing.
  7. Back up cloud data and test recovery.

Each layer addresses a different failure point. Multi-factor authentication may stop a stolen password, but it does not correct unrestricted file sharing. Email filtering may block many malicious messages, but it cannot protect an unmanaged home computer. Backup may restore deleted information, but it does not prevent an attacker from reading sensitive project files.

911 IT provides Microsoft cloud services and cybersecurity services for engineering firms that need secure identities, email, collaboration, devices, monitoring, and recovery.

1. Require Multi-Factor Authentication for Every Employee

Multi-factor authentication requires an employee to provide more than a password before accessing an account. It is one of the most important protections against stolen credentials.

Accounts That Should Require Multi-Factor Authentication

  • All employee Microsoft 365 accounts
  • Global and specialized administrator accounts
  • Remote-access accounts
  • Backup and security portals
  • Cloud CAD, BIM, and project-management platforms
  • Financial and payroll systems
  • Domain-registration and DNS accounts

Use Strong Authentication Methods

Not all multi-factor methods provide the same level of protection. Stronger methods include:

  • Passkeys
  • Hardware security keys
  • Certificate-based authentication
  • Microsoft Authenticator with number matching

Text-message codes can be better than password-only access, but they may be more vulnerable to social engineering, phone-number takeover, and interception. Higher-risk employees and administrators should use phishing-resistant methods whenever practical.

Eliminate Unapproved Exceptions

Common exceptions create major security gaps:

  • Executives who do not want to use multi-factor authentication
  • Shared project accounts
  • Old scanning or printing accounts
  • Service accounts using interactive login
  • Temporary contractors left outside security policies
  • Emergency accounts that are never monitored

Every exception should have a documented business reason, compensating controls, an owner, and a review date.

Block Legacy Authentication

Older authentication methods may allow applications to bypass modern security controls. The firm should identify and replace devices or applications that depend on outdated protocols.

Before blocking legacy access, test:

  • Scanners and multifunction printers
  • Older mobile devices
  • Accounting applications
  • Project-notification systems
  • Automated email services
  • Legacy engineering applications

2. Restrict Administrator Accounts and Privileges

Administrator accounts can change security policies, create users, access data, disable protection, and delete information. They should not be used for normal email, web browsing, or everyday work.

Separate Daily and Administrative Accounts

Each administrator should have:

  • A normal employee account for routine work
  • A separate named administrator account
  • Multi-factor authentication on both accounts
  • Only the permissions required for assigned duties

A technician who manages user passwords may not require the same access as someone who controls security policies, billing, applications, or all company data.

Limit Global Administrator Access

Global administrator access should be assigned to a very small number of trusted individuals. The firm should maintain enough emergency access to avoid lockout without giving broad privileges to every technician or vendor.

Review Administrative Roles Quarterly

A quarterly review should confirm:

  • Who has each administrator role
  • Why the access is required
  • When it was last used
  • Whether the person still works with the firm
  • Whether a lower-privilege role would be sufficient
  • Whether third-party provider access remains appropriate

Protect Emergency Accounts

Emergency or break-glass accounts may be needed when normal authentication systems fail. These accounts should have:

  • Long, unique credentials
  • Secure offline storage
  • Restricted use
  • Immediate alerts when accessed
  • Regular validation
  • Documented procedures

Control MSP Access

The engineering firm should know how its managed service provider accesses Microsoft 365.

Ask:

  • Does every technician use a named account?
  • Is technician access protected by multi-factor authentication?
  • Are privileges limited by role?
  • Are technician actions logged?
  • How quickly is access removed when an employee leaves the provider?
  • Can the engineering firm review active delegated access?

3. Detect Risky Sign-Ins and Account Compromise

Multi-factor authentication reduces risk but does not eliminate it. Attackers may use session-token theft, malicious applications, social engineering, compromised devices, or repeated approval prompts.

Monitor Sign-In Risk

Security monitoring should review:

  • Sign-ins from unexpected countries or regions
  • Impossible or unusual travel patterns
  • Repeated failed authentication attempts
  • Sign-ins from anonymous networks
  • New devices
  • Unexpected application access
  • Unusual mailbox activity
  • Changes to multi-factor authentication methods

Use Conditional Access

Conditional-access policies can allow, block, or restrict access based on factors such as:

  • User identity
  • Administrator role
  • Device compliance
  • Location
  • Application
  • Sign-in risk
  • Authentication method

A practical policy set may:

  • Require multi-factor authentication for all employees
  • Require stronger authentication for administrators
  • Block outdated authentication methods
  • Restrict access from unsupported devices
  • Block countries where the firm does not conduct business
  • Require managed devices for sensitive project information

Policies should be tested with a small group before broad enforcement. Incorrect rules can lock employees out of essential systems.

Respond to Suspicious Activity Immediately

A documented account-compromise process should include:

  1. Disable or restrict the affected account.
  2. Revoke active sessions and application tokens.
  3. Reset credentials using a trusted process.
  4. Review and reset authentication methods.
  5. Check mailbox rules, forwarding, delegates, and applications.
  6. Review SharePoint, OneDrive, and Teams activity.
  7. Search for malicious messages sent from the account.
  8. Notify affected employees, clients, or leadership when required.
  9. Document the incident and preventive improvements.

Watch for Malicious Mailbox Rules

Attackers may create inbox rules that hide replies, forward messages, delete warnings, or move financial correspondence into obscure folders.

Monitor for:

  • New external forwarding
  • Rules that delete messages
  • Rules using financial or security keywords
  • Unexpected mailbox delegates
  • Changes to shared mailboxes

4. Strengthen Email and Phishing Defenses

Email remains a common entry point for credential theft, ransomware, financial fraud, and malicious attachments.

Use Multiple Email Security Layers

A practical email defense program includes:

  • Spam and malware filtering
  • Link analysis
  • Attachment analysis
  • Impersonation protection
  • Domain authentication
  • External sender identification
  • User reporting tools
  • Security awareness training
  • Rapid investigation of reported messages

Protect Against Executive and Vendor Impersonation

Attackers may impersonate:

  • Owners and executives
  • Project managers
  • Accounting employees
  • Clients
  • Consultants
  • Construction partners
  • Software vendors
  • Insurance companies

Email security policies should detect messages that use a trusted person's display name from an outside address or a domain that differs slightly from the legitimate domain.

Configure Domain Authentication

The firm's domain should use email-authentication controls that help receiving systems distinguish legitimate mail from spoofed messages.

The configuration should be reviewed whenever the firm adds:

  • A marketing platform
  • A project-notification system
  • An accounting application
  • A customer relationship management tool
  • A recruiting platform
  • A website form service

Uncoordinated changes can cause legitimate email to fail authentication or weaken spoofing protection.

Train Employees with Engineering-Specific Examples

Generic annual training is not enough. Employees should practice recognizing messages involving:

  • Shared drawing or model notifications
  • Microsoft 365 password-expiration notices
  • Bluebeam or Autodesk document links
  • Updated payment instructions
  • Project bid invitations
  • Secure-file transfer requests
  • Fake multi-factor authentication prompts
  • Messages from compromised consultant accounts

Create a Simple Reporting Process

Employees should be able to report a suspicious message with one action. The security team should investigate quickly and remove confirmed threats from other mailboxes when possible.

Employees should know:

  • How to report suspicious email
  • Whom to call after entering a password
  • What to do after approving an unexpected authentication request
  • How to verify financial changes
  • When to stop using a computer

5. Manage Every Device That Accesses Company Information

Microsoft 365 security depends partly on the device used to access it. An unmanaged computer may contain malware, lack encryption, use an unsupported operating system, or share information with personal applications.

Requirements for Company-Owned Devices

Engineering workstations and laptops should generally have:

  • Centralized management
  • Supported operating systems
  • Automated security updates
  • Endpoint detection and response
  • Disk encryption
  • Restricted local administrator access
  • Automatic screen locking
  • Approved software
  • Remote lock or wipe capabilities where appropriate

Control Personal Device Access

The firm should decide whether personal devices may access:

  • Email
  • Teams
  • OneDrive
  • SharePoint
  • Project files
  • Client information
  • Regulated data

Possible controls include:

  • Blocking downloads to unmanaged devices
  • Allowing browser-only access
  • Requiring mobile application protection
  • Requiring device encryption and screen locks
  • Restricting sensitive applications to company devices

Manage Mobile Applications

Application-protection policies can separate company data from personal data on mobile devices. Policies may control:

  • Copying and pasting
  • Saving to personal storage
  • Opening files in unapproved applications
  • Offline access
  • Encryption
  • Remote removal of company data

Remove Access During Employee Offboarding

A documented offboarding process should:

  1. Disable the employee's account at the approved time.
  2. Revoke active sessions.
  3. Remove authentication methods.
  4. Recover company devices.
  5. Transfer mailbox and OneDrive data.
  6. Remove group, Teams, and SharePoint access.
  7. Review external sharing created by the employee.
  8. Remove access to third-party cloud applications.

Offboarding should be coordinated between management, human resources, and IT. Delayed notice can leave former employees with access to project and client information.

6. Control Teams, SharePoint, OneDrive, and External Sharing

Microsoft 365 makes collaboration easy, but convenience can lead to uncontrolled sharing, duplicate project files, outdated links, and excessive permissions.

Define Approved Storage Locations

Employees should know where different information belongs.

Information Type Typical Approved Location
Personal working documents Employee OneDrive
Team and department documents SharePoint or Teams-connected storage
Active CAD or BIM project data Approved engineering file platform tested for the workload
External client deliverables Approved secure sharing or project platform
Regulated information Restricted environment approved for the applicable requirement

Large AutoCAD, Civil 3D, or Revit workflows should be tested before moving them to a general-purpose synchronization platform. File locking, references, model relationships, path length, synchronization, and latency can affect usability.

Restrict Anonymous Sharing Links

Anonymous links may allow anyone with the link to access a file. For sensitive project information, use named-user access, expiration dates, and limited permissions.

Set External Sharing Standards

A practical external-sharing process should define:

  • Who may invite guests
  • Which sites permit external access
  • Whether guest approval is required
  • How long access remains active
  • Whether downloads are permitted
  • How access is reviewed
  • How confidential and regulated information is handled

Review Guest Accounts

Guest accounts may remain active after a consultant, client, or project partner no longer needs access. Review external users at least quarterly and remove unnecessary access.

Control Team and Site Creation

Allowing every employee to create unlimited Teams and SharePoint sites can produce duplicated files, confusing ownership, inconsistent permissions, and abandoned workspaces.

Establish standards for:

  • Naming
  • Ownership
  • External sharing
  • Retention
  • Archiving
  • Deletion

Use Data Classification

Information can be classified by sensitivity, such as:

  • Public
  • Internal
  • Confidential
  • Client restricted
  • Controlled or regulated

Labels and policies can help apply encryption, sharing restrictions, retention, and warnings based on the information type.

7. Back Up Microsoft 365 and Test Recovery

Microsoft 365 includes resiliency, retention, recycle bins, and version history, but those capabilities may not satisfy every recovery requirement.

An independent backup can provide additional protection against:

  • Accidental deletion
  • Malicious deletion
  • Compromised administrators
  • Ransomware synchronization
  • Retention misconfiguration
  • Departing employees
  • Short recovery windows

Microsoft 365 Data to Protect

  • Exchange Online mailboxes
  • Shared mailboxes
  • OneDrive
  • SharePoint
  • Teams files and related content
  • Calendars and contacts

Backup Security Requirements

The backup platform should include:

  • Separate administrator credentials
  • Multi-factor authentication
  • Restricted deletion rights
  • Documented retention
  • Monitoring for failures and changes
  • Regular restore testing

Recommended Recovery Tests

Recovery Test Suggested Frequency
Individual email or file Monthly
Mailbox or OneDrive folder Quarterly
SharePoint site content Quarterly
Departed employee data Semiannually
Large cloud recovery exercise At least annually

Learn more about business continuity services from 911 IT for protected cloud and server backups, disaster recovery, and restoration testing.

What Microsoft 365 Security Licensing Does an Engineering Firm Need?

The correct license depends on required security capabilities, compliance, endpoint management, phone systems, storage, analytics, and employee roles.

Planning should consider whether the firm needs:

  • Conditional access
  • Identity-risk detection
  • Endpoint management
  • Endpoint detection and response
  • Advanced email protection
  • Information protection
  • Retention and legal hold
  • Audit-log retention
  • Cloud application controls
  • Compliance capabilities

Do not select licensing solely by comparing application lists. Two plans may both include Outlook, Teams, Word, and Excel while providing very different security and management capabilities.

Use Different License Profiles When Appropriate

Not every employee necessarily needs the same plan. Common profiles may include:

  • Engineering and project employees
  • Executives and financial employees
  • Field employees
  • Administrative employees
  • Temporary contractors
  • Shared or kiosk devices

Licensing should be reviewed at least annually and whenever security requirements change.

A 90-Day Microsoft 365 Security Roadmap

Days 1–30: Secure Identities

  • Inventory users, administrators, guests, and applications.
  • Require multi-factor authentication.
  • Block outdated authentication.
  • Separate administrator accounts.
  • Review external forwarding and mailbox rules.
  • Remove former employees and unnecessary guests.
  • Document the account-compromise process.

Days 31–60: Secure Email, Devices, and Sharing

  • Improve impersonation, link, and attachment protection.
  • Configure domain email authentication.
  • Deploy or validate endpoint management.
  • Require encryption and supported operating systems.
  • Restrict access from unmanaged devices.
  • Review anonymous and external sharing.
  • Standardize Teams and SharePoint ownership.

Days 61–90: Monitor, Back Up, and Test

  • Implement identity and cloud activity monitoring.
  • Configure alerts for administrator and mailbox changes.
  • Protect Microsoft 365 data with independent backup.
  • Test mailbox, OneDrive, and SharePoint recovery.
  • Conduct a phishing exercise.
  • Run an account-compromise tabletop exercise.
  • Create an annual security roadmap and budget.

Example: A 40-Person Engineering Firm

Consider a Salt Lake City engineering firm with 40 employees using Microsoft 365, Teams, SharePoint, OneDrive, AutoCAD, Civil 3D, and several external project platforms.

The initial review identifies:

  • Seven employees without multi-factor authentication
  • Six global administrators
  • External mailbox forwarding
  • More than 80 inactive guest accounts
  • Anonymous sharing links with no expiration
  • Personal devices downloading company files
  • No independent Microsoft 365 backup
  • No documented account-compromise procedure

A 90-day improvement project could:

  1. Require multi-factor authentication for all employees.
  2. Reduce global administrators from six to two.
  3. Create separate administrator accounts.
  4. Remove external forwarding and abandoned guest accounts.
  5. Restrict anonymous links.
  6. Require managed devices for sensitive project data.
  7. Implement independent Microsoft 365 backup.
  8. Test mailbox and SharePoint recovery.
  9. Train employees using project-specific phishing scenarios.

The result is not a guarantee that no incident will occur. It substantially reduces common paths for account takeover, data exposure, and unrecoverable deletion while giving the firm a documented response process.

Common Microsoft 365 Security Mistakes

Assuming Microsoft Secures Everything Automatically

Microsoft protects the underlying cloud platform, but the customer must configure identities, permissions, devices, sharing, retention, and recovery.

Allowing Multi-Factor Authentication Exceptions

One unprotected account can provide attackers with access to email, files, contacts, and trusted business relationships.

Giving the MSP Permanent Global Administrator Access

Service-provider access should be named, limited, logged, and reviewed. Broad shared accounts increase risk and reduce accountability.

Using Email for Every Type of File Sharing

Email attachments create duplicated versions and reduce control. Approved project and collaboration platforms should be used for larger or sensitive information.

Leaving Guest Accounts Active Forever

Consultants and project partners may retain access long after the project ends unless guest access is reviewed.

Allowing Unmanaged Devices to Download Project Files

Information downloaded to a personal computer may fall outside company encryption, monitoring, backup, and remote-removal controls.

Treating Version History as a Complete Backup

Versioning is useful but may not protect against every deletion, retention change, administrator compromise, or large-scale recovery need.

Ignoring Third-Party Applications

Applications connected to Microsoft 365 may gain access to email, calendars, contacts, and files. Review application permissions and remove unused integrations.

Training Employees Only Once Per Year

Short, repeated training and realistic simulations are more effective than one annual presentation.

Microsoft 365 Security Checklist for Engineering Firms

  • Every employee uses multi-factor authentication.
  • Administrators use separate daily and privileged accounts.
  • Global administrator access is limited.
  • Legacy authentication is blocked.
  • Risky sign-ins and identity changes generate alerts.
  • Conditional-access policies are documented and tested.
  • External forwarding and suspicious mailbox rules are monitored.
  • Email impersonation, links, and attachments are filtered.
  • The firm's email domain has appropriate authentication controls.
  • Employees can report suspicious messages with one action.
  • Company devices are encrypted, patched, and centrally managed.
  • Access from personal devices is restricted according to policy.
  • Employee offboarding immediately removes cloud access.
  • Anonymous sharing is disabled or tightly restricted.
  • Guest accounts are reviewed at least quarterly.
  • Teams and SharePoint sites have assigned owners.
  • Sensitive and regulated information has defined storage locations.
  • Microsoft 365 data is independently backed up.
  • Mailbox, OneDrive, and SharePoint restores are tested.
  • The firm has a documented cloud incident-response process.

Every “no” or “not sure” answer identifies a potential route to account compromise, data exposure, or business interruption.

What Engineering Clients Say About 911 IT

“Great company! Always prompt to fix our problems right when they happen and very efficient and knowledgeable. Would highly recommend to anyone!”

— Scott, Engineering

Microsoft 365 security requires more than activating licenses. Engineering firms need responsive support, careful configuration, ongoing monitoring, employee training, controlled collaboration, and tested recovery.

Additional customer experiences are available on the 911 IT client testimonials page.

Frequently Asked Questions

Is Microsoft 365 secure enough for an engineering firm?

Microsoft 365 can support a strong security program when identity, email, devices, sharing, logging, retention, and backup are properly configured. Default settings alone may not satisfy the firm's risk, insurance, client, or compliance requirements.

Does every Microsoft 365 user need multi-factor authentication?

Yes. Every employee, administrator, contractor, and other interactive user should use multi-factor authentication unless a documented technical exception is supported by appropriate alternative controls.

Which multi-factor authentication method is best?

Passkeys, hardware security keys, certificate-based authentication, and properly configured authenticator applications generally provide stronger protection than text-message codes. Administrators and high-risk employees should use phishing-resistant authentication where practical.

Can an attacker bypass multi-factor authentication?

Attackers may steal session tokens, trick employees into approving requests, compromise devices, or abuse malicious applications. Multi-factor authentication should be combined with conditional access, monitoring, managed devices, and employee training.

Should an MSP have global administrator access?

An MSP may require privileged access for specific tasks, but access should be named, limited, protected by multi-factor authentication, logged, and reviewed. Permanent broad access for every technician is unnecessary and risky.

Should engineering firms allow personal devices to access Microsoft 365?

The decision depends on information sensitivity and business needs. Firms may allow restricted browser or mobile-app access while blocking downloads to unmanaged devices. Sensitive project or regulated data should generally require approved managed devices.

Is SharePoint appropriate for AutoCAD or Revit files?

SharePoint can work well for many business documents. Large, linked, or frequently edited CAD and BIM projects should be tested for synchronization, file locking, references, model behavior, path limitations, and recovery before migration.

Does Microsoft 365 include backup?

Microsoft provides resiliency, retention, recycle bins, and version history, but firms may still require an independent backup for longer retention, separate administration, granular recovery, and protection from accidental or malicious deletion.

How often should external Microsoft 365 users be reviewed?

Guest and external access should generally be reviewed at least quarterly. High-security or regulated environments may require monthly or project-based reviews.

How quickly should a compromised Microsoft 365 account be disabled?

A suspected compromised account should receive immediate attention. Active sessions should be revoked, credentials and authentication methods reviewed, and mailbox, file-sharing, and application activity investigated.

How much does Microsoft 365 security cost?

Additional licensing, management, monitoring, training, email security, endpoint protection, and backup may add approximately $15 to $75 per user per month. The actual cost depends on the firm's Microsoft plan, risk, compliance requirements, and existing tools.

Can Microsoft 365 support CMMC requirements?

Microsoft services can support many CMMC-related controls when the appropriate cloud environment, licensing, configuration, documentation, monitoring, and operating procedures are used. A standard subscription is not automatically a compliant environment.

Secure Microsoft 365 Without Slowing Engineering Work

A secure Microsoft 365 environment should protect identities, email, devices, project collaboration, and cloud data while allowing engineers to work efficiently. The strongest approach uses multiple coordinated layers rather than relying on one password, one security product, or one annual training session.

911 IT has served businesses in the Salt Lake City area since 2004 and helps engineering firms manage Microsoft 365, cloud security, employee devices, cybersecurity monitoring, backup, incident response, and strategic technology planning.

To evaluate your current Microsoft 365 security configuration, external sharing, administrator access, and recovery readiness, explore 911 IT cloud services or schedule a discovery call with 911 IT.