Team protected by a digital security shield from hackers, showcasing cloud-based cybersecurity and data protection icons.

How Should an Insurance Agency Secure Microsoft 365?

July 28, 2026

What Microsoft 365 Security Controls Does an Insurance Agency Need?

An insurance agency should protect Microsoft 365 with at least 10 core security controls: multi-factor authentication, separate administrator accounts, conditional access, email threat protection, device management, data-loss controls, secure file sharing, audit logging, independent backups, and a documented incident response process.

For an agency with 25–50 employees, Microsoft 365 often contains years of client correspondence, policy documents, claims information, financial records, employee data, and shared business files. A stolen password or poorly configured mailbox can therefore expose much more than one employee’s email.

The strongest strategy is to secure identities, devices, email, applications, and data as one connected system. Buying Microsoft 365 licenses is only the starting point. The agency must configure the available protections, monitor the environment, review access, train employees, and maintain a recovery plan.

The 10-Part Microsoft 365 Security Framework

  1. Require multi-factor authentication for every user.
  2. Separate administrator accounts from everyday accounts.
  3. Use conditional access to control risky sign-ins.
  4. Protect email from phishing and impersonation.
  5. Manage every device that accesses agency data.
  6. Control external sharing and sensitive information.
  7. Secure SharePoint, OneDrive, and Microsoft Teams.
  8. Monitor logs, alerts, forwarding rules, and account changes.
  9. Back up important Microsoft 365 data independently.
  10. Prepare an account-compromise and recovery plan.

Each control addresses a different type of risk. Multi-factor authentication may stop a stolen password, but it will not correct excessive file permissions. Email filtering may block malicious attachments, but it will not recover deleted data. Microsoft 365 security works best when these protections overlap.

1. Require Multi-Factor Authentication for Every User

Multi-factor authentication, commonly called MFA, requires a second verification step in addition to a password. That extra factor may be an authenticator application, hardware security key, device prompt, biometric verification, or temporary code.

MFA should protect:

  • Every employee mailbox
  • Agency owners and executives
  • Microsoft 365 administrators
  • Shared service accounts where supported
  • Remote and hybrid employees
  • Contractors with agency access
  • Accounts used by third-party applications

A criminal may obtain a password through phishing, credential reuse, malware, social engineering, or an unrelated data breach. MFA adds another barrier that can prevent the stolen password from becoming a successful login.

Use Stronger Authentication Methods Where Practical

Not all MFA methods provide the same protection. Text-message codes are generally better than password-only access, but authenticator applications and hardware security keys can provide stronger protection against several common attacks.

Agencies should establish an approved authentication method and avoid allowing users to choose the least secure option merely because it is more familiar.

Watch for MFA Fatigue Attacks

In an MFA fatigue attack, a criminal repeatedly sends authentication prompts and hopes the user approves one to make the interruptions stop. Employees should be trained to deny unexpected prompts and report them immediately.

An unexpected MFA request may indicate that someone already knows the employee’s password.

2. Separate Administrator Accounts From Everyday Accounts

Microsoft 365 administrators can change security settings, reset passwords, create accounts, access data, and grant additional privileges. Those capabilities make administrator accounts especially valuable to attackers.

Every administrator should use:

  • One standard account for email, browsing, and normal work
  • A separate privileged account for administrative tasks
  • Multi-factor authentication on both accounts
  • Only the administrative permissions required for the role
  • A documented approval and review process

An administrator should not use a highly privileged account to open routine attachments, browse the internet, or participate in normal email conversations.

Limit the Number of Global Administrators

Global administrator access should be restricted to the smallest practical number of qualified people. Many routine tasks can be completed with more limited roles, such as user administration, billing administration, or service-specific management.

Review privileged access at least quarterly and whenever an employee, vendor, or IT provider changes responsibilities.

Maintain Emergency Access

The agency should maintain a documented emergency-access process for situations in which normal administrative accounts become unavailable. Emergency accounts should be tightly controlled, monitored, and used only for their intended purpose.

3. Use Conditional Access to Control Risky Sign-Ins

Conditional access applies rules based on factors such as the user, device, location, application, and level of sign-in risk. It allows the agency to require stronger verification or block access when circumstances appear suspicious.

Conditional access policies may be used to:

  • Require MFA for Microsoft 365 access
  • Block outdated authentication methods
  • Restrict administrator access
  • Require compliant or approved devices
  • Limit access from unexpected countries or regions
  • Apply additional controls to sensitive applications
  • Block sign-ins identified as high risk
  • Protect SharePoint and OneDrive downloads on unmanaged devices

Test Policies Before Broad Deployment

A poorly planned access policy can lock out employees or interrupt important applications. Policies should be tested with a small group, documented, and deployed in stages.

Emergency accounts should also be considered so the agency does not lose administrative access because of a configuration mistake.

Disable Outdated Authentication

Older authentication methods may not support modern security protections such as MFA. Agencies should identify applications and devices that still depend on outdated login methods, migrate them when possible, and block unnecessary legacy access.

4. Protect Email From Phishing, Impersonation, and Fraud

Email is a primary target because employees routinely exchange documents, payment information, policy records, and sensitive requests through Microsoft Outlook.

A layered email security program should address:

  • Spam and malicious attachments
  • Phishing links
  • Executive impersonation
  • Lookalike domains
  • Compromised vendor accounts
  • Malicious forwarding rules
  • Unexpected payment instructions
  • Internal messages sent from compromised accounts

Microsoft 365 settings should be combined with appropriate email security, employee training, and verification procedures.

Protect Against Business Email Compromise

Business email compromise occurs when a criminal impersonates or controls a trusted mailbox. The attacker may request a payment, change deposit instructions, obtain client records, redirect a commission, or send additional phishing messages.

The agency should require independent verification for:

  • Banking-information changes
  • Wire-transfer requests
  • Unusual payment instructions
  • Requests for sensitive client records
  • Urgent requests that bypass normal procedures
  • Password and MFA reset requests
  • Changes to vendor contact information

Verification should use a known phone number or another trusted communication channel rather than replying to the original email.

Configure Domain Authentication

The agency should configure appropriate email-domain protections to make it harder for criminals to send messages that appear to come from the agency’s domain.

These controls require careful configuration and ongoing review, especially when third-party services send email on the agency’s behalf.

Give Employees a Simple Reporting Method

Employees should have a clear way to report a suspicious message without forwarding it casually to coworkers. The IT or security team should investigate reported messages and remove confirmed threats from other mailboxes when possible.

Recurring security awareness training should teach employees how to recognize and report suspicious messages. Learn more about layered protection through 911 IT’s cybersecurity services.

5. Manage Every Device That Accesses Agency Data

Microsoft 365 can be accessed from office computers, home laptops, tablets, and mobile phones. Identity security is important, but the agency must also consider the condition of the device receiving the data.

Every agency-managed device should have:

  • A supported operating system
  • Current security updates
  • Managed endpoint protection
  • Device encryption
  • Screen-lock requirements
  • Restricted local administrator access
  • Remote support and management capability
  • A documented owner and assigned user

Define Rules for Personal Devices

Employees who use personal devices may store business email, attachments, contacts, or files outside the agency’s normal controls. The agency should decide whether personal devices are permitted and what requirements apply.

A personal-device policy should address:

  • Required screen locks
  • Encryption
  • Minimum operating-system versions
  • Prohibited sharing with family members
  • Remote removal of agency data
  • Reporting lost or stolen devices
  • Separation of personal and business information
  • Access removal when employment ends

Block Unmanaged Downloads Where Appropriate

Conditional access and application policies can help limit what employees may download or synchronize to unapproved devices. Highly sensitive information may need to remain inside a managed browser session rather than being saved locally.

6. Control External Sharing and Sensitive Information

Microsoft 365 makes collaboration easy, but easy sharing can also expose files to the wrong person. Insurance agencies should configure sharing based on the sensitivity of the information and the recipient’s business need.

Review sharing settings for:

  • SharePoint sites
  • OneDrive folders
  • Microsoft Teams
  • Individual files
  • External guest accounts
  • Anonymous sharing links

Avoid Unrestricted Anonymous Links

An anonymous link may allow anyone who receives or forwards it to open the content. When client or agency information is involved, require authenticated access whenever practical and set expiration dates on external links.

Apply the Least-Access Principle

Employees should receive access only to the sites, folders, and information required for their roles. A producer may not need the same financial or human-resources access as an owner or accounting employee.

Permissions should be based on groups and roles rather than individually granting access without documentation.

Review External Guests

Guest access that was appropriate for a temporary project may remain active long after the work ends. Review external users regularly and remove accounts that no longer have a documented business purpose.

Protect Sensitive Data

Depending on the agency’s Microsoft licensing and requirements, information-protection controls may help identify or restrict the sharing of:

  • Social Security numbers
  • Financial account information
  • Payment card information
  • Driver information
  • Claims documentation
  • Employee records
  • Confidential business information

Automated controls should support employee judgment rather than replace clear data-handling policies.

7. Secure SharePoint, OneDrive, and Microsoft Teams

Microsoft 365 is more than email. SharePoint, OneDrive, and Teams can contain extensive records of agency operations and client communication.

SharePoint Security

Each SharePoint site should have:

  • A documented business purpose
  • At least one responsible owner
  • Role-based access groups
  • Appropriate external-sharing settings
  • A review schedule
  • A retention and deletion plan

Avoid creating new sites without a naming, ownership, and permission standard. Uncontrolled site creation can lead to duplicate files and inconsistent protection.

OneDrive Security

OneDrive is designed primarily for an individual employee’s working files. Important business records should not remain available only through one person’s account.

When an employee leaves, the agency should transfer ownership of required files and preserve them according to its retention obligations.

Microsoft Teams Security

Each Team may create associated conversations, files, membership groups, applications, and external access. Before creating a Team, define:

  • The business owner
  • Who may become a member
  • Whether guests are allowed
  • What type of information may be shared
  • How inactive Teams will be reviewed or archived

Control Third-Party Applications

Applications connected to Microsoft 365 may request access to email, calendars, contacts, files, or user profiles. Employees should not grant broad access to unfamiliar applications without review.

The agency should maintain an approval process for application permissions and periodically remove applications that are no longer required.

8. Monitor Logs, Alerts, Rules, and Account Changes

Security controls can fail without producing an obvious interruption. Monitoring helps identify suspicious activity before the attacker causes additional damage.

Important activities to monitor include:

  • Unusual sign-in locations
  • Repeated failed logins
  • Unexpected MFA requests
  • New administrator assignments
  • Password and authentication-method changes
  • Mailbox forwarding-rule creation
  • Mass file downloads
  • Large file deletions
  • Unusual external sharing
  • New third-party application permissions
  • Changes to security policies

Watch Mailbox Forwarding Rules

An attacker may create a hidden or unexpected forwarding rule that sends copies of email to an outside address. The criminal can then monitor conversations even after the employee changes a password.

After a suspected account compromise, review:

  • Inbox and forwarding rules
  • Delegated mailbox permissions
  • Sent and deleted items
  • Registered MFA methods
  • Active sign-in sessions
  • Connected applications
  • Administrative changes

Define Who Responds to Alerts

Generating an alert is not the same as responding to one. The agency should document who reviews alerts, when coverage is available, how urgent events are escalated, and what actions the responder is authorized to take.

9. Back Up Microsoft 365 Data Independently

Microsoft provides a resilient cloud platform, but availability is not the same as a complete agency-controlled backup strategy. Files and messages may be deleted accidentally, altered maliciously, encrypted through synchronized storage, or lost because retention settings do not match the agency’s needs.

An independent Microsoft 365 backup may protect:

  • Exchange Online mailboxes
  • SharePoint sites
  • OneDrive data
  • Microsoft Teams data supported by the backup platform

Questions to Ask About Microsoft 365 Backup

  1. Which Microsoft 365 services are protected?
  2. How frequently does backup occur?
  3. How long is data retained?
  4. Can one email or file be restored?
  5. Can an entire mailbox or site be restored?
  6. Where is the backup data stored?
  7. How is access to the backup platform protected?
  8. Who monitors failures?
  9. How often is restoration tested?
  10. What happens to former employee data?

The agency should also understand how long deleted users and their data remain available. Deleting an employee account before transferring required records can create a preventable loss.

Review backup and recovery planning through 911 IT’s business continuity services.

10. Prepare an Account-Compromise and Recovery Plan

The agency should assume that an employee will eventually click a convincing link, approve an unexpected prompt, or disclose a password. A documented response plan reduces confusion and limits the attacker’s time inside the environment.

Immediate Account-Compromise Response

  1. Notify the designated IT or security contact immediately.
  2. Block or disable the affected account when appropriate.
  3. Revoke active sessions and authentication tokens.
  4. Reset the password through a verified process.
  5. Review and replace unauthorized MFA methods.
  6. Inspect mailbox rules and forwarding settings.
  7. Review administrator-role changes.
  8. Inspect sign-in and audit activity.
  9. Identify messages, files, and contacts accessed by the attacker.
  10. Search for phishing messages sent from the compromised account.
  11. Remove malicious messages from other mailboxes where possible.
  12. Notify leadership, legal counsel, the insurance carrier, and other parties when required.

Do Not Stop After Changing the Password

A password reset alone may not remove an attacker. Active sessions, malicious forwarding rules, application permissions, alternate authentication methods, and messages sent to other employees may remain.

Preserve Evidence

Before making extensive changes, preserve appropriate logs and records. Those materials may be needed for investigation, legal review, cyber insurance, client communication, or reporting obligations.

Microsoft 365 Security Responsibilities by Role

Responsibility Agency Leadership IT Provider Employees
Security policies Approve requirements and risk decisions Recommend and implement technical controls Follow approved procedures
Account access Approve roles and exceptions Configure and review permissions Use only assigned accounts
Multi-factor authentication Require organization-wide adoption Deploy, monitor, and support MFA Protect authentication methods and report unexpected prompts
Email security Approve verification and payment procedures Configure filtering and investigate threats Verify unusual requests and report suspicious messages
File sharing Define acceptable use and data sensitivity Configure sharing controls and review access Share information only with authorized recipients
Backup Define recovery and retention needs Operate, monitor, and test the backup system Store business records in approved locations
Incident response Direct business, legal, and communication decisions Contain, investigate, and recover technical systems Report suspected incidents immediately

A 30-Day Microsoft 365 Security Improvement Plan

Days 1–5: Inventory and Assess

  • List every Microsoft 365 user and administrator.
  • Identify shared, service, former employee, and unused accounts.
  • Review the agency’s Microsoft licenses.
  • Inventory connected applications.
  • Document SharePoint sites, Teams, and external guests.
  • Review current backup and retention settings.

Days 6–10: Secure Identities

  • Require MFA for all users.
  • Create separate administrator accounts.
  • Reduce unnecessary global administrators.
  • Disable outdated authentication methods where possible.
  • Review password-reset and emergency-access procedures.

Days 11–15: Protect Email and Applications

  • Review anti-phishing and impersonation settings.
  • Verify domain authentication.
  • Inspect forwarding rules.
  • Review connected third-party applications.
  • Create an employee process for reporting suspicious messages.

Days 16–20: Secure Devices and Data

  • Confirm that every agency device is managed and encrypted.
  • Define personal-device requirements.
  • Review SharePoint and OneDrive sharing.
  • Remove unnecessary external guests.
  • Identify sensitive-data locations.

Days 21–25: Improve Monitoring and Recovery

  • Configure important security alerts.
  • Define alert-review and escalation responsibilities.
  • Deploy an appropriate Microsoft 365 backup.
  • Test mailbox and file restoration.
  • Document recovery procedures.

Days 26–30: Train and Test

  • Train employees on phishing and unexpected MFA prompts.
  • Practice the account-compromise response process.
  • Correct gaps identified during the exercise.
  • Deliver a security summary to agency leadership.
  • Schedule quarterly access and configuration reviews.

Microsoft 365 Security Checklist for Insurance Agencies

  • MFA is required for every employee.
  • Administrators use separate privileged accounts.
  • The number of global administrators is limited.
  • Legacy authentication is disabled where possible.
  • Conditional access policies are documented and tested.
  • Email phishing and impersonation protections are configured.
  • Employees can report suspicious messages easily.
  • Every agency device is supported, patched, encrypted, and protected.
  • Personal-device requirements are documented.
  • External file sharing is restricted appropriately.
  • Anonymous links are limited or disabled for sensitive information.
  • Guest accounts are reviewed regularly.
  • SharePoint sites and Teams have assigned owners.
  • Third-party application access is controlled.
  • Mailbox forwarding rules are monitored.
  • Important audit logs and security alerts are reviewed.
  • Microsoft 365 data is backed up independently where required.
  • Backup restoration is tested.
  • Former employee accounts follow a documented offboarding process.
  • An account-compromise response plan has been tested.

Common Microsoft 365 Security Mistakes

Mistake Potential Business Effect
MFA is optional A stolen password may provide direct access to email and files.
Administrators use privileged accounts for email A routine phishing message may expose broad administrative access.
Former employee accounts remain active Unused credentials may be exploited or accessed without authorization.
External sharing is unrestricted Sensitive files may be opened by unintended recipients.
Anonymous links never expire Access may continue long after the original business need ends.
Every user can approve applications Unreviewed third-party software may gain access to agency data.
No one monitors forwarding rules An attacker may secretly receive copies of agency email.
Cloud availability is mistaken for backup Deleted or altered information may not be recoverable as expected.
Personal devices are unmanaged Business data may be stored on insecure or shared equipment.
The response plan ends with a password reset Malicious sessions, rules, and application access may remain active.

A Practical Microsoft 365 Security Scenario

Consider a 40-person insurance agency using Exchange Online, Teams, SharePoint, and OneDrive. Employees work from one main office and several home locations.

A Microsoft 365 review identifies:

  • Five employees who have not completed MFA enrollment
  • Four global administrators using the same accounts for routine email
  • Two former employee accounts that remain licensed
  • Several anonymous file-sharing links with no expiration date
  • Guest users who no longer work with the agency
  • A third-party application with broad mailbox permissions
  • No separate Microsoft 365 backup
  • No documented account-compromise process

The agency creates a 30-day remediation plan:

  1. Require MFA for every user.
  2. Create separate administrator accounts.
  3. Reduce global administrator access.
  4. Disable former employee accounts and preserve required data.
  5. Replace anonymous links with authenticated access.
  6. Remove inactive guests and unnecessary applications.
  7. Implement Microsoft 365 backup and test restoration.
  8. Train employees and practice the compromise-response procedure.

The project does not require replacing Microsoft 365. It requires configuring, monitoring, and managing the platform according to the agency’s risk.

Questions to Ask an IT Provider About Microsoft 365

  1. Is MFA required for every user and administrator?
  2. Do administrators use separate privileged accounts?
  3. How do you review risky sign-ins?
  4. Which conditional access policies do you recommend?
  5. How do you protect against phishing and impersonation?
  6. Who investigates Microsoft 365 security alerts?
  7. How do you detect suspicious forwarding rules?
  8. How do you manage employee onboarding and offboarding?
  9. How often do you review administrator privileges?
  10. How are personal and unmanaged devices controlled?
  11. How do you review SharePoint, OneDrive, and Teams sharing?
  12. How are external guests removed?
  13. Who approves third-party applications?
  14. Which Microsoft 365 data is backed up?
  15. How often do you test restoration?
  16. What happens when an account is compromised?
  17. How long are security logs retained?
  18. Which protections are included in our managed IT agreement?
  19. Which Microsoft licenses or services cost extra?
  20. What security information will leadership receive?

Frequently Asked Questions

Is Microsoft 365 secure by default?

Microsoft 365 provides many security capabilities, but the agency must select suitable licenses, configure controls, manage users and devices, monitor alerts, and review the environment. Default settings may not match every agency’s risk or operational needs.

Does every Microsoft 365 user need MFA?

Every supported user should generally be protected by MFA, including owners, employees, administrators, remote workers, and contractors. Exceptions should be rare, documented, and protected through other controls.

Does MFA completely stop account compromise?

No. MFA greatly improves security, but criminals may still use social engineering, session theft, malicious applications, or repeated approval prompts. Agencies also need email security, employee training, monitoring, and incident response.

Should Microsoft 365 administrators have separate accounts?

Yes. Separate privileged accounts reduce the risk that everyday email, browsing, or document activity will expose administrative access.

Can Microsoft 365 replace email security training?

No. Technical controls can block many threats, but employees still need to identify suspicious requests, unexpected MFA prompts, payment fraud, impersonation, and unusual sharing activity.

Does Microsoft automatically back up all agency data?

Microsoft provides service availability, retention, and recovery features, but those capabilities may not satisfy the agency’s backup and restoration requirements. The agency should evaluate an independent backup for Exchange, SharePoint, OneDrive, and Teams data.

How often should Microsoft 365 permissions be reviewed?

Review privileged access, guest accounts, external sharing, and important group memberships at least quarterly and whenever employees, vendors, or agency responsibilities change.

What should happen when an employee leaves?

The agency should disable access at the approved time, revoke active sessions, preserve required data, transfer file ownership, remove group and application access, recover licenses, and document completion.

Can employees use personal phones for Microsoft 365?

Personal-device access may be allowed when the agency has documented requirements and appropriate controls. The agency should be able to protect business data and remove agency access when the device is lost or the employee leaves.

What should an employee do after approving an unexpected MFA prompt?

The employee should contact the designated IT or security team immediately. The account may need to be disabled, sessions revoked, authentication methods reviewed, and activity investigated.

How can the agency prevent unsafe file sharing?

Use authenticated sharing, expiration dates, restricted guest access, role-based permissions, and employee training. Review external links and guest accounts regularly.

Who should manage Microsoft 365 security?

Agency leadership should approve policies and risk decisions. A qualified internal IT team or managed service provider should configure, monitor, document, and test the technical controls. Employees remain responsible for following approved procedures and reporting suspicious activity.

Build Microsoft 365 Security Around Identities, Devices, and Data

Microsoft 365 can give an insurance agency secure email, collaboration, document management, and remote access, but only when the environment is actively managed.

Start with the 10-part framework:

  1. Require MFA.
  2. Separate administrator accounts.
  3. Apply conditional access.
  4. Protect email.
  5. Manage devices.
  6. Control sensitive information and external sharing.
  7. Secure SharePoint, OneDrive, and Teams.
  8. Monitor logs, alerts, and account changes.
  9. Back up important data.
  10. Practice account-compromise response.

Review these controls at least quarterly and whenever the agency hires employees, changes IT providers, adds a location, adopts a new application, completes an acquisition, or prepares for cyber insurance renewal.

911 IT provides cloud and Microsoft 365 services, cybersecurity services, managed IT services, and backup and business continuity planning for organizations that need secure, dependable technology.

Need to identify security gaps in your Microsoft 365 environment? Schedule a discovery call with 911 IT to review your MFA coverage, administrator access, email security, file sharing, devices, backups, and incident response process.