Microsoft 365 Security Checklist for Vaughan Law Firms

For many Vaughan law firms, Microsoft 365 has quietly become the centre of the business.

Email is in Outlook and Exchange Online.

Documents are in SharePoint and OneDrive.

Meetings happen in Teams.

Staff sign into computers using Microsoft accounts.

And more firms are now adding Microsoft 365 Copilot.

That means a stolen Microsoft 365 account can give an attacker access to a lot more than email.

The problem is that many firms assume Microsoft takes care of all of the security.

Microsoft protects the Microsoft 365 platform. But the customer is still responsible for things such as user accounts, access permissions, security settings, devices and its own data governance. Microsoft describes this as the shared responsibility model.

For a law firm holding confidential client information, Microsoft 365 should not simply be installed.

It should be properly secured.

Here is what we would check.


1. Require MFA for Every User

Start here.

Every lawyer, law clerk, assistant, administrator and staff member should have multi-factor authentication protecting their Microsoft 365 account.

Microsoft recommends protecting users through MFA using Microsoft Entra security controls such as Conditional Access. Microsoft also provides Security Defaults for organizations that do not use more advanced Conditional Access policies.

For Vaughan law firms, we’d go a step further.

Higher-risk users should use stronger authentication methods where practical.

That includes:

  • Partners
  • Managing lawyers
  • Accounting staff
  • People handling trust funds
  • Microsoft 365 administrators
  • IT administrators

The Canadian Centre for Cyber Security now recommends phishing-resistant MFA and points to methods such as FIDO2 security keys, passkeys and Windows Hello for Business.

Check:

☐ Every Microsoft 365 account has MFA

☐ Administrator accounts use strong MFA

☐ Weak authentication methods are being phased out where practical

If someone can still get into a firm’s Microsoft 365 account using only a password, fix that first.


2. Use Conditional Access

MFA is good.

Conditional Access is better.

Conditional Access lets the firm decide under what conditions someone should be allowed into Microsoft 365.

For example, the firm might require stronger authentication when someone signs in from an unusual location or require certain users to connect from a managed device.

Microsoft recommends Conditional Access as its preferred method for applying MFA where the required licensing is available.

Depending on the firm’s Microsoft licensing and risk level, policies can be built around:

  • MFA
  • User location
  • Device compliance
  • Risky sign-ins
  • Applications
  • Administrator accounts

Microsoft also supports policies that can require MFA, a compliant managed device or other access conditions before allowing a user into resources.

Check:

☐ Conditional Access policies are configured where licensing allows

☐ Policies apply to all appropriate users

☐ Administrator accounts have stronger rules

☐ Policy exclusions are documented

That final item matters.

We’ve seen environments where security policies were created but half the company was excluded from them because someone had trouble signing in two years ago.

That’s not much of a security policy.


3. Block Legacy Authentication

Some older email applications and protocols were built before modern MFA became common.

Attackers like that.

Microsoft specifically recommends blocking legacy authentication because older authentication methods may not support modern security controls properly. Conditional Access can be used to block legacy authentication requests.

Check:

☐ Legacy authentication is blocked

☐ Old applications requiring legacy authentication have been identified

☐ Exceptions have a documented business reason

Don’t keep an old security hole open forever because one person still uses an ancient email application.


4. Separate Microsoft 365 Administrator Accounts

Your Microsoft 365 administrator should not use their powerful administrator account to read normal email and browse the internet all day.

Administrative accounts should be separate.

That way, compromising someone’s normal email account does not automatically give an attacker administrative access to Microsoft 365.

Microsoft’s guidance recommends stronger controls for privileged users and reducing exposure of high-value administrator accounts.

Check:

☐ Administrators have separate admin accounts

☐ Normal user accounts aren’t Global Administrators

☐ Admin privileges are limited to people who actually need them

☐ Admin activity can be reviewed

There should be very few Global Administrators in a small or mid-sized law firm.

Not ten.

Not every partner.

And definitely not every employee.


5. Create Emergency Access Accounts

What happens if your normal administrator accounts stop working?

Microsoft recommends maintaining at least two emergency access accounts.

These are sometimes called break-glass accounts.

They are there for unusual situations where normal administrator access fails.

Microsoft currently recommends cloud-only emergency accounts with phishing-resistant authentication and no dependency on the firm’s normal authentication infrastructure.

Check:

☐ Emergency administrator accounts exist

☐ They are securely protected

☐ Their use is monitored

☐ The procedure for using them is documented

You don’t want to invent your emergency access process during an emergency.


6. Secure Email Against Phishing

Law firms live in Outlook.

Attackers know that too.

A fake Microsoft login page can look nearly identical to the real one.

So can fake SharePoint notifications, DocuSign requests, invoices and file-sharing messages.

Microsoft Defender for Office 365 can add protections such as Safe Links and Safe Attachments, depending on the firm’s licensing.

Safe Links checks URLs used in phishing attacks, including time-of-click checks. Safe Attachments can open suspicious attachments in a virtual environment before delivery to see whether they behave like malware or ransomware.

Microsoft also publishes recommended Standard and Strict preset security policies for Defender for Office 365 environments.

Check:

☐ Anti-phishing policies are configured

☐ Malicious links are inspected

☐ Attachments receive advanced scanning where supported

☐ Impersonation protection is configured

☐ High-risk users receive stronger protection

Basic spam filtering isn’t the same thing as a proper email security program.


7. Configure SPF, DKIM and DMARC

These three acronyms matter.

SPF, DKIM and DMARC help other mail systems determine whether an email claiming to come from your firm really came from an approved source.

That can make it harder for someone to impersonate your law firm’s domain.

Microsoft recommends using SPF, DKIM and DMARC together for custom Microsoft 365 email domains.

Check:

☐ SPF is configured correctly

☐ DKIM signing is enabled

☐ DMARC is configured

☐ Other systems sending email as the firm are included properly

That might include billing systems, newsletters, scanners, practice-management software or marketing platforms.

DMARC shouldn’t be set once and forgotten.

Someone should know what is sending email using your domain.


8. Control External Email Forwarding

A compromised mailbox can be very useful to an attacker.

One trick is creating a rule that quietly forwards email outside the firm.

The lawyer continues receiving email normally.

But the attacker receives a copy too.

Microsoft allows organizations to control or block automatic external forwarding and notes that forwarding can create a risk of information disclosure.

Check:

☐ Automatic external forwarding is blocked unless required

☐ Existing forwarding rules are reviewed

☐ Exceptions are documented

A law firm’s email should not quietly forward to somebody’s Gmail account just because it was convenient five years ago.


9. Lock Down SharePoint and OneDrive Sharing

SharePoint and OneDrive make sharing files easy.

Sometimes too easy.

A user can send a document outside the firm in seconds.

That may be exactly what the firm wants when sharing documents with a client.

But external sharing needs rules.

Microsoft allows administrators to control external sharing across SharePoint and OneDrive and can restrict which users are permitted to share externally.

Check:

☐ External sharing settings have been reviewed

☐ “Anyone” links are restricted where appropriate

☐ Only approved users can share externally where practical

☐ Old guest access is reviewed

☐ Sensitive sites have tighter sharing rules

A family-law file and the office Christmas party photos probably don’t need the same sharing policy.


10. Review Guest Users

Microsoft 365 makes it easy to invite clients, consultants and outside parties into Teams and SharePoint.

The problem comes later.

The matter closes.

The consultant leaves.

Nobody removes the account.

Now the firm has guest users that nobody remembers.

Check:

☐ Guest accounts are reviewed regularly

☐ Guests who no longer need access are removed

☐ Access to sensitive SharePoint sites is reviewed

☐ Guest access has an owner inside the firm

Microsoft provides administrators with controls for managing external sharing and guest access across SharePoint and OneDrive.

Think of guest access like handing someone a key.

Eventually, you should ask whether they still need it.


11. Control Third-Party Application Access

This is becoming a bigger issue.

Employees constantly connect apps to Microsoft 365.

Scheduling tools.

AI tools.

PDF software.

CRM systems.

Mobile applications.

Productivity tools.

When a user clicks Accept, that application may receive permission to access Microsoft 365 data.

Microsoft recommends controlling user consent and limiting consent to trusted applications, such as apps from verified publishers.

Check:

☐ User application consent is controlled

☐ Connected applications are reviewed

☐ Old applications are removed

☐ High-risk permissions require administrator approval

This is especially relevant now that employees are trying new AI applications every week.

A free app shouldn’t automatically get access to client email because someone clicked a button.


12. Manage the Computers Accessing Microsoft 365

Protecting Microsoft 365 accounts while ignoring the laptops accessing those accounts only solves half the problem.

A law firm’s computers should also be managed.

Microsoft Intune can apply device security and compliance policies, depending on licensing. It can also manage BitLocker encryption on Windows devices.

Check:

☐ Firm computers are centrally managed

☐ Disk encryption is enabled

☐ Security policies are applied

☐ Unsupported computers are blocked or replaced

☐ Lost devices can be dealt with quickly

For firms using Microsoft 365 Business Premium, Microsoft Defender for Business is included and provides endpoint protection capabilities designed for organizations with up to 300 users.

The Microsoft 365 account and the device accessing it should be treated as one security problem.


13. Monitor Sign-Ins and Security Alerts

Microsoft 365 produces a lot of useful security information.

Failed logins.

Risky sign-ins.

Administrator activity.

Malware detections.

Changes to accounts.

Unusual activity.

Someone should actually look at it.

Microsoft Entra ID Protection can identify risky users and risky sign-ins, with additional capabilities depending on licensing. Microsoft also supports Conditional Access policies that react to detected sign-in risk.

Check:

☐ Microsoft 365 security alerts are monitored

☐ Suspicious sign-ins are investigated

☐ Administrator activity is reviewed

☐ Someone receives high-risk alerts

A security alert that nobody reads isn’t very useful.


14. Keep Audit Logging Available

When something goes wrong, one of the first questions is:

What happened?

Microsoft 365 audit logs can record activity across Microsoft 365 services. Microsoft says audit logging is enabled by default for Microsoft 365 organizations, though available events and retention periods vary by licensing.

For a law firm, logs can become very important during an investigation.

Check:

☐ Audit logging is available

☐ The firm understands how long logs are retained

☐ Log retention matches the firm’s investigation needs

☐ Security events can be searched when required

Finding out your logs disappeared before you discovered an incident isn’t a good outcome.


15. Have an Offboarding Process

When someone leaves the firm, deleting their name from the website is not enough.

Their Microsoft 365 access needs to be dealt with immediately.

That may include:

  • Blocking sign-in
  • Revoking sessions
  • Resetting passwords
  • Removing group membership
  • Removing administrator rights
  • Transferring OneDrive data
  • Managing their mailbox
  • Removing mobile-device access
  • Reviewing application access

Microsoft specifically identifies inactive accounts as a security risk and provides tools to identify accounts that are no longer being used.

Check:

☐ Departing users are disabled quickly

☐ Access is removed from all connected systems

☐ Firm data is retained or transferred properly

☐ Old accounts are reviewed regularly

Someone who left the firm six months ago shouldn’t still be able to log in.


16. Set Data Retention Rules Deliberately

Microsoft 365 can retain email and documents according to policies configured through Microsoft Purview.

But the correct retention period is not an IT decision.

The firm’s legal, professional, client and business requirements should determine what information needs to be kept and for how long.

Microsoft provides retention policies and retention labels that can apply to Exchange, SharePoint, OneDrive and other Microsoft 365 content.

Check:

☐ Microsoft 365 retention settings have been reviewed

☐ Policies reflect the firm’s actual requirements

☐ Old default settings aren’t being mistaken for a records policy

☐ Someone owns the firm’s data-retention decisions

Technology can enforce the rule.

It shouldn’t invent the rule.


17. Back Up Microsoft 365 Data

Microsoft runs a highly resilient cloud platform.

That is not the same thing as having the recovery plan your law firm needs.

Microsoft’s shared-responsibility model states that customers remain responsible for their data, identities and configurations in SaaS environments. Microsoft also now offers Microsoft 365 Backup for Exchange Online, SharePoint and OneDrive.

Your firm should decide what recovery capability it requires for:

  • Exchange email
  • OneDrive
  • SharePoint
  • Teams-related data
  • Microsoft 365 configurations
  • Identity information where applicable

That may involve Microsoft-native backup capabilities or another Microsoft 365 backup platform.

Check:

☐ Microsoft 365 is included in the firm’s backup strategy

☐ Recovery requirements are documented

☐ Backup jobs are monitored

☐ Restore tests are performed

The important question isn’t:

“Does Microsoft back things up?”

The useful question is:

“If we lose 50,000 client files tomorrow, how quickly can our firm recover them?”


18. Review Microsoft Secure Score

Microsoft gives organizations a built-in tool called Microsoft Secure Score.

Secure Score measures the firm’s security posture against Microsoft’s recommended security actions. Microsoft also lets organizations track the score and recommendations over time.

It isn’t a certification.

And getting 100% isn’t necessarily the goal.

Some recommendations may not fit your environment.

But ignoring Secure Score completely wastes a useful tool.

Check:

☐ Secure Score is reviewed regularly

☐ Recommended actions are investigated

☐ Accepted risks are documented

☐ The score is tracked over time

Your IT provider should be able to explain why the score changed.


Quick Microsoft 365 Security Checklist for Law Firms

Ask your IT provider whether these controls are in place:

  • ☐ MFA protects every user
  • ☐ Stronger MFA protects administrator accounts
  • ☐ Conditional Access is configured where appropriate
  • ☐ Legacy authentication is blocked
  • ☐ Administrator accounts are separate
  • ☐ Emergency admin accounts exist
  • ☐ Email phishing protection is configured
  • ☐ Safe Links and Safe Attachments are used where licensed
  • ☐ SPF is configured
  • ☐ DKIM is configured
  • ☐ DMARC is configured
  • ☐ External email forwarding is controlled
  • ☐ SharePoint external sharing is restricted
  • ☐ OneDrive external sharing is restricted
  • ☐ Guest users are regularly reviewed
  • ☐ Third-party application access is controlled
  • ☐ Firm devices are centrally managed
  • ☐ Firm laptops are encrypted
  • ☐ Security alerts are monitored
  • ☐ Audit logs are available
  • ☐ Departing-user access is removed quickly
  • ☐ Data-retention policies have been reviewed
  • ☐ Microsoft 365 data has a recovery and backup strategy
  • ☐ Restore testing is performed
  • ☐ Microsoft Secure Score is reviewed

How many can your firm confidently check?

More importantly:

How many can your IT provider prove?


Why This Matters for Vaughan Law Firms

This isn’t only a Microsoft issue.

It connects directly to how lawyers use technology.

The Law Society of Ontario’s Rules of Professional Conduct state that lawyers should understand the benefits and risks associated with technology relevant to their practice, while recognizing their duty to protect confidential information.

The Law Society also maintains specific resources dealing with technology security, data protection, cybersecurity and remote work.

If most of your firm’s client communication and documents now pass through Microsoft 365, the security of that environment becomes part of managing the risk around client information.

That does not mean Microsoft 365 needs to be complicated.

It means somebody needs to manage it properly.


Microsoft 365 Security Shouldn’t Be “Set It and Forget It”

This is one of the biggest problems we see with cloud services.

A company moves to Microsoft 365.

Someone turns on MFA.

A few policies get configured.

Then nobody looks at the environment for three years.

Meanwhile:

People join.

People leave.

New applications get connected.

Guest users are invited.

Sharing links accumulate.

Microsoft adds new security features.

Threats change.

Security settings need ongoing management.

For a Vaughan law firm, we would expect Microsoft 365 security to be reviewed regularly and included in the firm’s normal cybersecurity reporting.

A quarterly review could show:

  • MFA coverage
  • Administrator accounts
  • Secure Score
  • Risky sign-ins
  • Security incidents
  • Devices under management
  • Encryption status
  • External sharing
  • Guest accounts
  • Backup status
  • Restore testing
  • Outstanding security recommendations

That gives the firm’s partners something much more useful than:

“Microsoft 365 is fine.”


How Atomic Guardian Secures Microsoft 365 for Law Firms

Atomic Guardian provides managed IT services and cybersecurity for law firms in Vaughan, Toronto and across the GTA.

Microsoft 365 security is a major part of that work.

We help law firms manage identity security, MFA, Conditional Access, administrator accounts, Microsoft Defender, endpoint protection, email security, SharePoint and OneDrive access, device management, backups, monitoring and ongoing security reporting.

The goal is not to turn the managing partner into a Microsoft engineer.

The goal is much simpler.

Your firm should be able to answer:

Who has access to our Microsoft 365 environment?

How are they being protected?

What happens if an account gets compromised?

Can we recover our data?

Can our IT provider prove these controls are working?

If those answers aren’t clear, the checklist above is a good place to start.

This article provides general technology and cybersecurity information and is not legal advice. Microsoft 365 capabilities vary by subscription and licensing. Ontario law firms should refer to current Law Society of Ontario guidance and obtain professional advice when determining their legal, privacy and professional obligations.

Related industry guidance

Put this guidance into practice

Connect these recommendations to a complete technology and risk-management program. Explore Atomic Guardian’s Microsoft 365 security and IT support for law firms, including Microsoft 365, legal applications, cybersecurity, vendor coordination, backups, and strategic planning.

For help applying this checklist in your environment, see Atomic Guardian’s Microsoft 365 security hardening service.