Cartoon dog in suit presenting cloud software security with Microsoft 365 apps to amazed businesspeople in office.

How Should Microsoft 365 Be Configured for Attorneys?

August 03, 2026

Configure Microsoft 365 Around 10 Security and Productivity Controls

A law firm should configure Microsoft 365 around 10 essential controls: secure authentication, risk-based access, protected administrator accounts, managed devices, controlled document sharing, matter-based permissions, email protection, information retention, audit monitoring, and tested recovery.

For a 25–50 employee law firm, Microsoft 365 should make routine legal work easier while applying stronger safeguards to unusual or high-risk activity. Attorneys should be able to access email, collaborate on documents, work remotely, and communicate with clients without repeatedly fighting security prompts or creating unsafe workarounds.

The correct configuration depends on the firm’s Microsoft licensing, legal applications, client requirements, retention obligations, device strategy, and risk tolerance. However, every law firm should be able to answer four questions:

  1. Who can access the environment?
  2. Which information can each person reach?
  3. How will suspicious activity be detected?
  4. How will information be recovered after deletion, compromise, or disruption?

Use this 10-part framework to evaluate whether Microsoft 365 is configured for confidential legal work rather than merely activated with default settings.

1. Require Strong Authentication for Every User

Passwords alone are not sufficient protection for law firm email, documents, calendars, contacts, and cloud applications.

Multi-factor authentication should be required for:

  • Every attorney and employee
  • Firm administrators
  • Outside contractors
  • IT support personnel
  • Guest users where appropriate
  • Accounts connected to third-party applications

Use phishing-resistant methods for high-risk accounts

Text-message codes and approval prompts are stronger than passwords alone, but they can still be targeted through phishing, social engineering, and repeated notification attacks.

Partners, finance personnel, administrators, and other high-risk users should be evaluated for stronger authentication methods such as:

  • Passkeys
  • Hardware security keys
  • Windows Hello for Business
  • Certificate-based authentication where appropriate

Eliminate shared user accounts

Every person should sign in through an individual account. Shared credentials make it difficult to determine who accessed information, weaken offboarding, and increase the impact of a compromised password.

When multiple employees need access to the same function, use:

  • Shared mailboxes
  • Microsoft 365 groups
  • Delegated permissions
  • Teams channels
  • SharePoint groups
  • Role-based application access

These options allow collaboration while preserving individual accountability.

2. Use Conditional Access to Apply Security Based on Risk

Conditional Access allows the firm to evaluate the context of a sign-in before granting access. Policies can consider the user, device, location, application, authentication method, and detected risk.

A practical law firm configuration may:

  • Require MFA for every user.
  • Block outdated authentication methods.
  • Require stronger verification for administrators.
  • Restrict access from unsupported devices.
  • Require managed devices for sensitive applications.
  • Block access from prohibited countries or regions when appropriate.
  • Require additional verification for unusual sign-ins.
  • Apply stronger controls to guests and outside vendors.

Avoid broad rules that interrupt normal legal work

A policy that blocks every unfamiliar situation without testing may prevent attorneys from working while traveling, entering court facilities, visiting clients, or using approved temporary equipment.

Conditional Access policies should be introduced through a controlled process:

  1. Identify the security objective.
  2. Review affected users and applications.
  3. Test the policy with a limited group.
  4. Use reporting or simulation modes where available.
  5. Document required exceptions.
  6. Communicate the change to employees.
  7. Monitor results after enforcement.

Exceptions should be specific, approved, documented, and reviewed. Permanently excluding an executive or senior attorney because a control is inconvenient creates avoidable risk.

3. Protect Microsoft 365 Administrator Accounts

An attacker who compromises a highly privileged account may be able to create users, change security policies, access data, disable protections, or authorize malicious applications.

A law firm should limit the number of people with administrative privileges and assign only the permissions required for each person’s responsibilities.

Separate daily and administrative accounts

IT personnel and administrators should not use highly privileged accounts for everyday email, web browsing, document editing, or routine communication.

Each administrator should have:

  • A normal account for daily work
  • A separate account for administrative tasks
  • Strong MFA on both accounts
  • Only the administrative roles required
  • Documented approval for privileged access

Reduce Global Administrator assignments

Not every administrative task requires the Global Administrator role. Microsoft 365 includes more limited roles for functions such as user management, Exchange administration, SharePoint administration, Teams administration, security, and billing.

The firm should review privileged roles at least quarterly and remove access that is no longer necessary.

Maintain protected emergency-access accounts

The firm should maintain controlled emergency accounts for situations in which normal administrative access is unavailable.

These accounts should:

  • Be used only for emergency recovery
  • Have unique, securely stored credentials
  • Be monitored for any sign-in activity
  • Be excluded only from policies that would prevent emergency use
  • Be tested through a documented procedure
  • Be reviewed regularly

The law firm—not an outside provider alone—should retain appropriate ownership and recovery access to its Microsoft 365 tenant.

4. Connect Access to Managed and Encrypted Devices

An attorney may have a valid password and MFA method while signing in from a personal, infected, or unencrypted computer. Identity security and device security should work together.

Firm-managed computers should have:

  • Full-disk encryption
  • Endpoint detection and response
  • Automatic security updates
  • Managed application patching
  • Screen-lock requirements
  • Restricted administrator privileges
  • Remote monitoring and support
  • Documented ownership and lifecycle status

Define the personal-device policy

The firm should decide whether attorneys and employees may access email or documents from personal computers, phones, and tablets.

Possible approaches include:

  • Prohibiting access from personal computers
  • Allowing browser-only access with limited download capability
  • Requiring device enrollment before access
  • Managing only the firm’s applications and information
  • Allowing mobile email while blocking local file storage

The selected policy should reflect the sensitivity of the firm’s information, employee workflows, client commitments, and ability to support the devices.

Control mobile access

Mobile policies should address:

  • Device encryption
  • Screen locks and biometrics
  • Minimum operating-system versions
  • Copying firm information into personal applications
  • Downloading attachments
  • Remote removal of firm data
  • Lost or stolen device reporting

A mobile device should not become an unmanaged copy of the firm’s mailbox and confidential documents.

5. Structure SharePoint, OneDrive, and Teams Around Legal Work

Microsoft 365 collaboration tools should have distinct purposes.

A practical model is:

  • OneDrive: An individual employee’s active working files and drafts
  • SharePoint: Firm, department, client, or matter information that belongs to the organization
  • Teams: Communication and collaboration connected to an approved team or project
  • Exchange Online: Email, calendars, contacts, and shared mailboxes

Important client and matter information should not remain permanently in an individual employee’s OneDrive when it belongs to the firm.

Create an approved information structure

Before moving documents, determine:

  • Which files belong in the legal document-management system
  • Which content belongs in SharePoint
  • When Teams should be created
  • Who approves new workspaces
  • Who owns each site or team
  • How outside guests are approved
  • When inactive workspaces are archived
  • How information is transferred when an employee leaves

Avoid uncontrolled Teams and SharePoint growth

When every employee can create unlimited sites, teams, groups, and external sharing links, the firm may lose visibility into where confidential information is stored.

A governance process should define:

  • Naming standards
  • Creation approvals
  • Required owners
  • Permitted guests
  • Expiration or review dates
  • Archiving procedures
  • Deletion procedures

The purpose is not to prevent collaboration. It is to ensure that each workspace has an accountable owner and an appropriate lifecycle.

6. Control External Sharing With Clients and Third Parties

Law firms routinely share information with clients, experts, co-counsel, vendors, courts, and opposing counsel. Emailing attachments is not always the safest or most manageable option.

SharePoint and OneDrive can support controlled external sharing, but the settings should reflect the sensitivity of legal information.

Use authenticated sharing by default

For confidential content, recipients should generally authenticate before opening a shared file or folder.

The sharing process should support:

  • Access for named recipients
  • Expiration dates
  • View-only permissions where appropriate
  • Restrictions on resharing
  • Removal of access when the need ends
  • Activity logs
  • Periodic guest reviews

Restrict anonymous links

Links that work for anyone who receives them may be convenient, but they can be forwarded beyond the intended audience.

If anonymous links are permitted, the firm should define:

  • Which users may create them
  • Which sites may use them
  • Maximum expiration periods
  • Whether downloads are allowed
  • Which types of information are prohibited

For highly confidential client or matter information, authenticated sharing is generally the safer default.

Limit who can share externally

Not every employee necessarily needs authority to invite outside users. The firm may restrict external sharing to specific attorneys, administrators, practice groups, or trained employees.

Review guest access quarterly

A guest who needed access during an active matter may not need access six months later.

The review should identify:

  • The guest
  • The sponsoring attorney or employee
  • The sites, teams, and files available
  • The business reason for access
  • The date access was last used
  • Whether access should continue

7. Apply Matter-Based and Role-Based Permissions

Microsoft 365 should not give every employee access to every document merely because they work for the same firm.

Permissions may need to reflect:

  • Practice group
  • Assigned matters
  • Job responsibilities
  • Client requirements
  • Ethical walls
  • Financial responsibilities
  • Human resources confidentiality
  • Leadership duties

Assign permissions through groups

Whenever possible, assign access through defined groups rather than granting rights directly to dozens of individual users.

Group-based access makes onboarding, transfers, reviews, and offboarding more consistent.

Protect sensitive internal information

Information requiring restricted access may include:

  • Employee records
  • Partner compensation
  • Firm financial information
  • Cyber insurance documents
  • Administrative credentials
  • Incident response records
  • Internal investigations
  • Conflict information
  • Restricted client matters

Review permissions at least quarterly

The firm should verify:

  • Former employees have no access.
  • Transferred employees no longer retain unnecessary permissions.
  • Guests remain sponsored by an active employee.
  • Owners are assigned to important sites and teams.
  • Administrative privileges remain appropriate.
  • Ethical walls and restricted matters are functioning as intended.

Permission reviews should produce a dated record showing what was reviewed, which exceptions were found, and who is correcting them.

8. Harden Exchange Online and Law Firm Email

Email remains one of the highest-risk Microsoft 365 services because it combines confidential information, unfamiliar senders, attachments, document links, payment requests, and urgent deadlines.

A law firm’s email configuration should address:

  • Spam and phishing filtering
  • Malicious attachment inspection
  • Malicious link protection
  • Impersonation attempts
  • Lookalike domains
  • Suspicious mailbox rules
  • Automatic external forwarding
  • Unusual login activity
  • Bulk deletion or message access
  • Sender authentication

Configure SPF, DKIM, and DMARC

These email authentication controls help receiving systems determine whether a message claiming to come from the firm’s domain was sent through an authorized source.

Implementation should be planned carefully because the firm may use multiple approved services to send email, including:

  • Microsoft 365
  • Practice-management platforms
  • Billing systems
  • Marketing services
  • Electronic signature applications
  • Website forms
  • Scanning or notification systems

Moving to a stronger DMARC enforcement policy should follow an inventory and monitoring process so legitimate messages are not unexpectedly blocked.

Block automatic external forwarding unless approved

Attackers frequently create forwarding rules to receive copies of confidential messages without continuing to sign in to the compromised mailbox.

External forwarding should be blocked by default or limited to documented business cases.

Protect payment and account-change workflows

Microsoft 365 cannot independently verify that a wire instruction or bank-account change is legitimate.

The firm should require employees to confirm high-risk requests through a known phone number or direct conversation, especially when a message involves:

  • Wire transfers
  • Settlement payments
  • Payroll changes
  • Vendor bank information
  • Password resets
  • Unexpected document-sharing requests
  • Changes to client contact information

Review cybersecurity services for help coordinating identity protection, email security, endpoint monitoring, and incident response.

9. Define Retention, Deletion, and Legal Hold Responsibilities

Microsoft 365 retention should be configured around the firm’s approved legal, ethical, contractual, insurance, and business requirements.

The IT provider should not independently decide how long the firm must retain client or matter information. Firm leadership and qualified counsel should approve the policy.

Separate retention from backup

Retention and backup serve different purposes.

  • Retention preserves or disposes of information according to a policy.
  • Backup provides a separate recovery path after deletion, corruption, compromise, or disruption.

A retention policy may prevent deletion for a defined period, but it should not automatically be treated as a complete business continuity or recovery strategy.

Document the lifecycle of legal information

The firm should determine:

  • Which communications and documents constitute official records
  • Where official matter records belong
  • How long different categories are retained
  • When information may be deleted
  • How closed matters are archived
  • How legal holds are initiated and released
  • Who approves exceptions
  • How departed-employee information is handled

Do not treat every mailbox as permanent storage

Email may contain official matter information, but individual mailboxes are not always the appropriate permanent repository. The firm should define when messages or attachments must be moved into the practice-management or document-management system.

Coordinate legal holds carefully

When litigation, investigation, or another preservation obligation arises, the firm should follow an approved legal-hold process.

The process should identify:

  • The responsible attorney
  • The affected custodians
  • The systems containing relevant information
  • The date preservation begins
  • The search and export procedures
  • The documentation retained
  • The approval required before release

10. Monitor Activity and Test Recovery

Microsoft 365 security requires ongoing monitoring. A secure configuration can weaken over time as employees join or leave, vendors connect applications, sharing expands, and administrators make changes.

The firm or its IT provider should monitor for events such as:

  • Risky or unusual sign-ins
  • Unexpected administrator assignments
  • New third-party application consent
  • Suspicious inbox rules
  • Large downloads or deletions
  • Unusual external sharing
  • Security settings being disabled
  • Unexpected forwarding
  • Emergency-account activity
  • Changes to retention or audit settings

Define who responds to alerts

A security alert is only useful when someone reviews it and has authority to respond.

Ask:

  • Who monitors Microsoft 365 alerts?
  • Is monitoring available outside business hours?
  • How are critical events escalated?
  • Can a compromised account be disabled immediately?
  • Can active sessions be revoked?
  • Who contacts firm leadership?
  • How are response actions documented?

Protect Microsoft 365 data with an appropriate recovery strategy

The firm should determine how it will recover after:

  • Accidental deletion
  • Malicious deletion
  • Account compromise
  • Ransomware synchronization
  • Incorrect retention changes
  • Application failure
  • Employee departure

The recovery design may include native Microsoft recovery features, retention controls, version history, recycle bins, and a separate Microsoft 365 backup service where the firm’s requirements justify it.

Run documented recovery tests

At least quarterly, the firm should test recovery of selected Microsoft 365 information.

A test may restore:

  • An email message
  • A mailbox folder
  • A OneDrive file
  • A SharePoint document library
  • A Teams-connected file
  • A deleted user’s information

The report should record:

  • What was restored
  • Which recovery method was used
  • How long the recovery took
  • Whether permissions and versions were preserved
  • Whether the restored information was usable
  • Which corrective actions remain

Review business continuity services for assistance with protected backups, restoration testing, disaster recovery, and continuity planning.

Use a Five-Zone Microsoft 365 Access Model

A 25–50 employee law firm can simplify Microsoft 365 governance by organizing access into five zones.

Zone Typical information Recommended access
1. Firm-wide Policies, announcements, general templates All current employees
2. Department or practice group Team procedures, resources, working documents Members of the relevant group
3. Client or matter Matter documents and collaboration Assigned legal team and approved participants
4. Restricted Ethical walls, investigations, sensitive clients Specifically approved users only
5. Administrative HR, finance, security, credentials, partner records Authorized administrative personnel

Every SharePoint site, Team, group, or shared workspace should fit within a defined zone. The classification should influence membership, external sharing, review frequency, and retention.

A Practical Configuration for a 35-Employee Law Firm

Consider a Salt Lake City law firm with 35 employees, Microsoft 365, remote attorneys, a cloud practice-management system, and regular document sharing with clients and experts.

A practical Microsoft 365 configuration could include:

  • Individual accounts for all 35 employees
  • MFA for every employee
  • Phishing-resistant authentication for partners and administrators
  • Conditional Access that blocks outdated authentication
  • Managed-device requirements for sensitive applications
  • Separate accounts for administrative work
  • Two protected emergency-access accounts
  • Encrypted and monitored firm laptops
  • Restricted access from personal computers
  • Authenticated external file sharing
  • Expiration dates for guest access
  • Group-based SharePoint permissions
  • Quarterly guest and administrator reviews
  • SPF, DKIM, and DMARC configuration
  • Blocked automatic external forwarding
  • 24/7 monitoring of critical security alerts
  • Approved retention and legal-hold procedures
  • Separate recovery protection where required
  • Quarterly restoration testing

Most of these controls operate in the background. Attorneys sign in securely, access the information assigned to them, share documents through an approved process, and contact a live technician when a security control interferes with legitimate work.

Example: Sharing Documents With an Outside Expert

An attorney needs to provide an outside expert with access to 25 confidential documents for 30 days.

An unsafe process might involve attaching the documents to several emails or sending an unrestricted public link.

A controlled Microsoft 365 process would:

  1. Place approved copies in a designated SharePoint location.
  2. Give access to the expert’s named email address.
  3. Require the expert to authenticate.
  4. Limit access to the specific folder.
  5. Set an expiration date.
  6. Restrict resharing.
  7. Record the sponsoring attorney.
  8. Remove access when the assignment ends.

The attorney receives a repeatable process that is both safer and easier to manage than multiple email attachments.

Example: Offboarding a Departing Attorney

When an attorney leaves, the firm should not simply reset the person’s password.

The offboarding process should include:

  1. Disable sign-in at the approved time.
  2. Revoke active sessions.
  3. Remove MFA methods and registered devices.
  4. Remove administrative roles.
  5. Transfer mailbox and OneDrive information.
  6. Remove the user from Teams, groups, and SharePoint access.
  7. Remove access to third-party applications.
  8. Preserve required information.
  9. Configure approved email handling.
  10. Recover firm equipment.
  11. Update the asset and account inventory.
  12. Document completion.

A standardized process reduces the risk that former employees retain access to client information.

What Attorneys Should Experience

A properly configured Microsoft 365 environment should feel consistent rather than restrictive.

Attorneys should be able to:

  • Sign in through a secure but understandable process.
  • Access approved information from firm-managed devices.
  • Share files through a standard method.
  • Reach email and documents while traveling.
  • Receive immediate assistance when access fails.
  • Understand where official matter information belongs.
  • Report suspicious activity without navigating a complex process.

They should not need to:

  • Use personal email to send large files.
  • Create public links because approved sharing is too difficult.
  • Reuse shared passwords.
  • Store client documents on unmanaged personal devices.
  • Wait until the next business day for urgent access help.
  • Guess whether a security warning is legitimate.

Security is strongest when the approved workflow is also the simplest way to complete the work.

What Law Firm Clients Value in Microsoft 365 Support

Customer feedback collected by 911 IT repeatedly connects cloud security with responsive, knowledgeable support.

Clients value a technology partner that:

  • Understands the organization’s existing systems
  • Responds quickly when access is interrupted
  • Explains security controls in understandable language
  • Manages cloud settings proactively
  • Coordinates interconnected applications and vendors
  • Remains involved until the issue is fully resolved

One legal-services client described depending on responsive technical support for email, court filing, legal research, and document access. The client emphasized the value of reaching a live technician who could resolve problems remotely and patiently explain the solution.

Another client praised 911 IT for safely managing cloud-based services, including Microsoft 365, while allowing the organization to focus on its core work.

These experiences demonstrate that Microsoft 365 configuration and help desk service cannot be separated. Strong security controls require fast assistance when an attorney encounters a legitimate access problem.

25-Point Microsoft 365 Checklist for Law Firms

  • Every employee uses an individual account.
  • MFA is enforced for all users.
  • High-risk users have phishing-resistant authentication.
  • Outdated authentication methods are blocked.
  • Conditional Access policies have been tested and documented.
  • Administrative accounts are separate from daily user accounts.
  • The number of Global Administrators is limited.
  • Emergency-access accounts are protected and monitored.
  • The firm controls its Microsoft 365 tenant and recovery information.
  • Firm laptops are encrypted and managed.
  • Personal-device access follows a written policy.
  • OneDrive, SharePoint, and Teams have defined purposes.
  • Every important site or Team has at least one accountable owner.
  • External sharing requires approval or follows a documented standard.
  • Anonymous links are restricted.
  • Guest access is reviewed quarterly.
  • Permissions are assigned through groups where practical.
  • Restricted matters and administrative information have limited access.
  • SPF, DKIM, and DMARC are configured.
  • Automatic external forwarding is restricted.
  • Critical security alerts are actively monitored.
  • Third-party application access is reviewed.
  • Retention requirements have been approved by the firm.
  • A Microsoft 365 recovery strategy is documented.
  • A real restoration test has been completed within the last quarter.

Any answer of “no,” “probably,” or “we assume our provider handles it” should become a documented action item with an owner and deadline.

Common Microsoft 365 Configuration Mistakes

Assuming Microsoft 365 is secure by default

Microsoft provides extensive security capabilities, but the firm remains responsible for licensing decisions, configuration, access, monitoring, employee behavior, third-party applications, and recovery planning.

Giving every IT technician Global Administrator access

Administrative permissions should match job responsibilities. Broad access increases the consequences of a compromised account or human error.

Allowing unrestricted external sharing

Uncontrolled links and guest accounts can remain active long after the original business need ends.

Using OneDrive as the permanent matter repository

An employee’s OneDrive is not always the correct location for records that belong to the firm or must remain accessible after that employee leaves.

Keeping former employee accounts licensed and active

Departed employees should be processed through a documented offboarding workflow that disables access while preserving required information.

Confusing retention with backup

Retention may preserve information according to policy, but it does not automatically provide every recovery capability the firm requires.

Ignoring third-party application permissions

Applications connected to Microsoft 365 may receive access to mailboxes, files, calendars, contacts, or organizational data. Those permissions should be approved and reviewed.

Making security so difficult that attorneys bypass it

When secure file sharing, remote access, or software approval is unnecessarily slow, employees may use personal email, unapproved cloud storage, or other unsafe alternatives.

Frequently Asked Questions

Is multi-factor authentication required for every law firm employee?

MFA should be treated as a foundational control for all employees, administrators, and remote users. High-risk accounts should be evaluated for stronger phishing-resistant authentication.

Should attorneys be allowed to use personal computers?

The firm should make a documented decision based on confidentiality, client requirements, device-management capability, and workflow needs. Many firms restrict sensitive access to managed and encrypted computers.

Should law firms use OneDrive or SharePoint?

Most firms use both. OneDrive is appropriate for an individual’s working files, while SharePoint is better for information that belongs to a team, department, client, matter, or the firm. A legal document-management system may remain the official repository for matter records.

Can a law firm securely share files with clients through Microsoft 365?

Yes. SharePoint and OneDrive can provide authenticated external sharing, expiration, limited permissions, and access removal. The firm should configure and govern those features rather than allowing unrestricted sharing.

How many Global Administrators should a firm have?

Keep the number as low as operationally practical. Use narrower administrative roles for routine duties and maintain protected emergency access for recovery.

Does Microsoft back up Microsoft 365 data?

Microsoft operates resilient cloud services and provides native retention and recovery features. The firm should evaluate whether those features meet its required recovery time, retention, independence, and restoration needs or whether a separate backup service is appropriate.

How often should Microsoft 365 permissions be reviewed?

Administrative roles, guests, external sharing, and sensitive workspace permissions should generally be reviewed at least quarterly and after staffing, matter, or vendor changes.

Who should own the Microsoft 365 tenant?

The law firm should retain appropriate ownership and recovery control. An MSP may administer the tenant, but essential accounts, domains, subscriptions, and documentation should not be controlled exclusively by the provider.

Can Microsoft 365 replace a legal document-management system?

Sometimes, but not automatically. The decision depends on matter workflows, email filing, document profiling, versioning, ethical walls, integrations, search, records management, and user requirements.

How often should Microsoft 365 recovery be tested?

Critical recovery processes should be tested on a recurring schedule, often quarterly. The test should restore real information and document whether it was complete, usable, and recovered within the expected timeframe.

Configure Microsoft 365 for Legal Work, Not Generic Office Use

A law firm should not treat Microsoft 365 as a collection of licenses. It is an identity platform, communication system, collaboration environment, information repository, security control, and critical part of daily legal operations.

A defensible configuration combines 10 areas:

  1. Strong authentication
  2. Risk-based access
  3. Protected administration
  4. Managed devices
  5. Governed collaboration
  6. Controlled external sharing
  7. Matter-based permissions
  8. Hardened email
  9. Approved retention
  10. Monitored and tested recovery

When these controls are designed around legal workflows, attorneys gain secure access without unnecessary friction, administrators gain visibility, and partners gain clearer evidence that confidential information is being protected.

911 IT helps Utah law firms configure, secure, monitor, and support Microsoft 365 with live 24/7 assistance, local on-site service, managed cybersecurity, cloud expertise, business continuity, and proactive planning.

Explore our cloud services, review our cybersecurity services, read the six questions law firms should ask their IT provider every quarter, or schedule a 10-minute discovery call to review your Microsoft 365 security and configuration.