
Your law firm uses Microsoft 365 every day.
Attorneys communicate through Outlook. Paralegals collaborate on documents. Administrative teams schedule meetings through Teams. Employees access files through OneDrive and SharePoint.
But here's an important question:
Just because your law firm uses Microsoft 365, does that mean your firm's information is properly protected?
Not necessarily.
Microsoft 365 provides numerous security capabilities, but the protections your firm receives depend on your subscription, configuration, security policies, and how employees use the technology.
A poorly configured environment can create opportunities for unauthorized access, accidental information sharing, account compromise, and business disruption.
For law firms, those risks are particularly concerning because your systems contain confidential client communications, legal documents, financial information, discovery materials, and other sensitive records.
The good news?
You don't necessarily need to replace your existing technology to improve security.
You may need to take a closer look at how it's configured.
Let's examine 10 Microsoft 365 security settings every North Texas law firm should review.
What Are the Most Important Microsoft 365 Security Settings for Law Firms?
The most important areas to review include multifactor authentication, administrator privileges, email security, external file sharing, data loss prevention, device management, legacy authentication, audit logging, and backup and recovery.
These controls work together to reduce unauthorized access, protect sensitive information, and improve your firm's ability to detect and respond to security incidents.
However, there is no universal configuration that fits every law firm. Your security requirements will depend on your practice areas, client obligations, employee workflows, existing technology, and Microsoft 365 licensing.
Here are 10 areas worth reviewing.
1. Multifactor Authentication: Is Everyone Protected?
Imagine someone obtains an attorney's Microsoft 365 password through a phishing email.
Without additional protection, that password could potentially provide access to the attorney's email, files, and other connected business applications.
Multifactor authentication (MFA) adds another verification requirement beyond a password.
Depending on the method, employees may verify their identity through an authenticator application, security key, passkey, or another approved authentication method.
Microsoft offers security defaults as a baseline protection option and Conditional Access policies for organizations that require more customization. Microsoft Security Defaults | Microsoft MFA
What your law firm should review:
- Is MFA enforced for every applicable user?
- Are administrator accounts protected with phishing-resistant authentication?
- Are authentication methods reviewed regularly?
- Are exceptions documented and appropriately controlled?
- Are employees trained to recognize suspicious authentication requests?
MFA significantly strengthens account security, but not all authentication methods provide the same level of protection.
For privileged accounts, phishing-resistant methods deserve particular consideration.
Datatex Tech Tip
Don't assume MFA is configured correctly simply because employees occasionally receive authentication prompts.
Ask your IT provider to verify which accounts are protected, which authentication methods are permitted, and whether any accounts or applications bypass your policies.
2. Administrator Privileges: Who Has the Keys to Your Entire Firm?
Your Microsoft 365 administrator accounts can have extensive control over your organization's technology environment.
Depending on their assigned roles, administrators may manage users, change security policies, modify permissions, and access sensitive administrative functions.
That makes these accounts particularly attractive targets.
One important principle is called least privilege.
It means employees and administrators should receive only the permissions necessary to perform their responsibilities.
Microsoft recommends protecting privileged accounts, separating everyday accounts from administrative accounts, and using privileged access management where appropriate. Microsoft Zero Trust | Microsoft Baseline Settings
What your law firm should review:
- How many employees or outside vendors have administrative privileges?
- Does everyone with administrator access still need it?
- Are administrative accounts separate from everyday email accounts?
- Is phishing-resistant MFA required for privileged accounts?
- Are administrator activities monitored?
Consider what would happen if a compromised administrator account allowed an attacker to change your firm's security settings.
Restricting administrative access can reduce that risk.
3. Email Security: Are Phishing Attacks Getting Through?
Email remains central to legal operations.
Your attorneys receive communications from clients, courts, opposing counsel, financial institutions, and vendors.
Unfortunately, cybercriminals can exploit those same communication channels.
Consider this scenario.
An attorney receives an email that appears to come from a familiar client. The message contains an attachment supposedly related to an active case.
The attorney opens it.
But the attachment contains malicious content.
Microsoft Defender for Office 365 provides additional email-security capabilities, including Safe Links, Safe Attachments, and enhanced anti-phishing protections, depending on licensing and configuration. Microsoft Defender Security Policies | Microsoft Defender Anti-Phishing
What your law firm should review:
- Are anti-phishing policies properly configured?
- Are suspicious attachments analyzed before delivery?
- Are malicious links checked?
- Are important individuals and business domains protected against impersonation?
- Are suspicious messages quarantined appropriately?
- Have SPF, DKIM, and DMARC been configured for your firm's email domains?
Microsoft provides Standard and Strict preset security policies. Organizations should evaluate which protections are appropriate for their users and confirm that the intended policies are actually enabled. Microsoft Defender Security Policies | Microsoft Defender Get Started
Email security is particularly important for firms handling financial transactions, settlement instructions, confidential attachments, and sensitive client correspondence.
Remember, no email filter catches every malicious message. Employee awareness and verification procedures remain important.
4. SharePoint and OneDrive: Who Can Access Your Client Files?

Here's a situation worth considering.
An employee needs to share a document with an outside consultant.
They generate a sharing link and email it.
Simple, right?
But what if that link allows anyone who possesses it to access the document?
What if it provides editing permissions when the recipient only needs to read the file?
And what if the link remains active long after the project is finished?
Microsoft 365 provides controls for managing external sharing through SharePoint and OneDrive. Administrators can establish organizational and site-level restrictions, and supported sensitivity-label configurations can influence sharing behavior. Microsoft Protect Collaborative Workspaces | Microsoft Configure Sharing Link Type
What your law firm should review:
- Are anonymous sharing links permitted?
- Are sharing links restricted to specific people when appropriate?
- Can employees share sensitive documents outside the organization without additional approval?
- Are external guest accounts reviewed?
- Are unnecessary permissions removed?
- Are default sharing permissions appropriately restricted?
For firms working with outside counsel, expert witnesses, consultants, and other third parties, external collaboration is often necessary.
The goal isn't to eliminate sharing.
It's to ensure that information is shared with the appropriate people under appropriate controls.
5. Data Loss Prevention: Can Sensitive Information Leave Your Firm?
Your law firm may have strong passwords, MFA, and excellent email filtering.
But what happens when an authorized employee accidentally sends a confidential document to the wrong person?
Or shares a spreadsheet containing sensitive client information with someone outside the organization?
This is where Data Loss Prevention (DLP) becomes important.
Microsoft Purview provides tools that can help organizations identify and protect sensitive information. Depending on licensing and configuration, DLP policies can help restrict certain types of information sharing across supported Microsoft 365 applications. Microsoft Guide to Mitigate Data Leakage | Microsoft Protect Collaborative Workspaces
For law firms, this may include protecting documents containing financial records, personal identifiers, and other confidential information.
What your law firm should review:
- Has sensitive information been classified appropriately?
- Are DLP policies configured where needed?
- Are employees warned when attempting to share restricted information?
- Are sensitive documents protected with appropriate permissions?
- Are exceptions monitored and documented?
One important distinction: DLP isn't a substitute for employee training, confidentiality procedures, or appropriate access controls.
It's an additional layer of protection.
6. Device Management: Can Any Laptop Access Your Firm's Files?
Your attorneys don't always work from the office.
They may access documents from home, attend hearings remotely, work while traveling, or review files from mobile devices.
Remote access provides flexibility.
But it also introduces security considerations.
Consider an attorney who accesses confidential client files using a personal laptop that hasn't received security updates in months.
Should that device have unrestricted access to your firm's Microsoft 365 environment?
Microsoft Intune can help organizations manage devices and evaluate whether they meet defined security requirements. When integrated with Microsoft Entra Conditional Access, device-compliance information can influence whether a device receives access to protected resources. Microsoft Device Compliance Policies | Microsoft Compliance Policies
What your law firm should review:
- Are firm-owned laptops and mobile devices centrally managed?
- Are devices required to meet appropriate security standards?
- Is device encryption enabled where appropriate?
- Can IT remove business information from managed devices when necessary?
- Are personal devices subject to appropriate access restrictions?
- Are operating systems and security applications regularly updated?
Your firm's policies should balance employee productivity with the need to protect sensitive client information.
7. Legacy Authentication: Are Older Applications Creating Security Gaps?
Some older applications use authentication methods that don't support modern security protections.
These are commonly called legacy authentication protocols.
An outdated application or service may create an opportunity for attackers to bypass protections designed around modern authentication.
Microsoft recommends blocking legacy authentication as part of its security baseline and provides relevant controls through security defaults and Conditional Access. Microsoft Security Defaults | Microsoft Baseline Settings
What your law firm should review:
- Are legacy authentication methods blocked where appropriate?
- Are older applications still connecting to Microsoft 365?
- Have any exceptions been created?
- Are exceptions documented and reviewed?
- Can outdated applications be upgraded or replaced?
Be careful about making changes without understanding your environment.
Older applications, multifunction printers, and certain integrations may require special attention.
Your IT provider should identify dependencies and plan changes before disabling authentication methods.
8. Email Forwarding: Could Your Messages Be Going Somewhere Else?
Imagine a cybercriminal gains access to an employee's mailbox.
Instead of immediately stealing information, the attacker creates a rule that automatically forwards incoming messages to an external email address.
Your employee continues using email normally.
Meanwhile, confidential correspondence may be sent somewhere it doesn't belong.
Microsoft Exchange Online provides controls for restricting automatic external email forwarding. Microsoft recommends explicitly configuring the desired forwarding behavior rather than assuming an organization's default settings provide the intended protection. Microsoft Spam Policies | Microsoft Automatic Email Forwarding
What your law firm should review:
- Is automatic forwarding to external addresses appropriately restricted?
- Are mailbox forwarding configurations reviewed?
- Are suspicious inbox rules investigated?
- Are exceptions limited to legitimate business requirements?
- Are administrators alerted to suspicious mailbox activity where supported?
For firms exchanging confidential documents, settlement information, and sensitive client correspondence, this deserves attention.
9. Audit Logging: Would You Know if Something Suspicious Happened?
Preventing security incidents is important.
But your firm also needs visibility when something goes wrong.
Imagine discovering that confidential files may have been accessed without authorization.
Could your IT team determine which account accessed the information?
Could it identify suspicious sign-in activity?
Would sufficient records be available to investigate?
Microsoft Purview auditing provides capabilities for recording and searching supported user and administrator activities. Availability, recorded events, and retention depend on the organization's configuration and licensing. Microsoft Learn Auditing Solutions | Microsoft Turn Auditing On or Off
What your law firm should review:
- Is appropriate audit logging enabled and verified?
- Are relevant Microsoft 365 activities being recorded?
- Are audit records retained for an appropriate period?
- Can authorized personnel access the logs when needed?
- Are important security alerts configured?
- Is there a documented incident-response process?
Collecting logs is only part of the solution.
Your organization also needs a process for reviewing alerts, investigating suspicious activity, and responding to incidents.
For law firms, those capabilities can be particularly valuable when investigating potential unauthorized access to confidential information.
10. Backup and Recovery: Can You Restore Your Data When It Matters?
Here's a question every managing partner should ask:
If our law firm lost access to its Microsoft 365 information tomorrow, how quickly could we recover?
Microsoft 365 provides availability, retention, recovery, and data-protection capabilities. However, these features are not interchangeable, and they may not satisfy every firm's backup and recovery requirements.
Consider what could happen if:
- An employee accidentally deletes important files.
- A compromised account deletes or alters information.
- Ransomware disrupts access to synchronized documents.
- Important email messages are lost.
- Your firm needs to recover information outside its available retention period.
Your organization should have a documented backup and recovery strategy that reflects its actual business requirements.
Microsoft offers Microsoft 365 Backup capabilities, and third-party backup solutions are also available. The appropriate solution depends on your licensing, retention requirements, recovery objectives, and the information you need to protect.
What your law firm should review:
- Is Microsoft 365 information included in your backup strategy?
- Are Exchange Online, SharePoint, and OneDrive covered appropriately?
- Have you established acceptable recovery times?
- Are backup copies protected against unauthorized modification or deletion?
- Is backup access restricted?
- Have you tested your ability to restore important information?
- Does your backup strategy align with applicable retention and preservation obligations?
Your law firm shouldn't discover that its recovery strategy is inadequate during an emergency.
Datatex Tech Tip
Ask your IT provider to demonstrate a successful recovery rather than simply confirming that backups are running.
A successful backup and a successful restoration are two different things.
Your Microsoft 365 Security Checklist for 2026
Not sure where to begin? Use this checklist during your next meeting with your IT provider.
Check each item as you review it.
- Multifactor authentication is enforced for applicable users.
- Administrator privileges are restricted and regularly reviewed.
- Email security and anti-phishing protections are properly configured.
- SharePoint and OneDrive external sharing is appropriately restricted.
- Sensitive information is protected through classification and DLP where appropriate.
- Laptops and mobile devices meet established security requirements.
- Legacy authentication is blocked, with necessary exceptions documented.
- Automatic external email forwarding is appropriately restricted.
- Audit logging and security monitoring are configured and verified.
- Microsoft 365 backup and recovery procedures are documented and tested.
Remember, checking a box doesn't mean a setting is necessarily configured correctly. Your IT provider should verify the configuration and document any changes that are needed.
How Does Microsoft 365 Security Connect to AI?
This is an important consideration for law firms exploring Microsoft Copilot and other AI applications.
AI tools can make it easier to locate, summarize, and analyze information.
But that also makes existing data permissions increasingly important.
Imagine your firm has a SharePoint folder containing sensitive information that was accidentally shared too broadly.
An authorized employee who already has access to that folder may be able to discover its contents more easily through an AI tool connected to Microsoft 365.
The underlying problem isn't necessarily AI.
It's the existing permissions.
Before expanding your firm's use of AI, review your Microsoft 365 security foundation.
This includes identity management, access permissions, sensitive information classification, employee training, and appropriate AI governance policies.
For more information, read our related articles:
- Your Attorneys Are Already Using AI. Does Your Law Firm Know Where the Data Is Going?
- Should Your Law Firm Have an AI Acceptable Use Policy? What to Include in 2026
Frequently Asked Questions About Microsoft 365 Security for Law Firms
Is Microsoft 365 secure enough for law firms?
Microsoft 365 offers security capabilities that can support law firms, including multifactor authentication, access management, email protection, data loss prevention, and auditing.
However, security depends on licensing, configuration, employee practices, and the firm's overall cybersecurity program.
Simply subscribing to Microsoft 365 does not guarantee that every necessary protection has been implemented.
Does Microsoft 365 automatically protect against phishing?
Microsoft 365 includes built-in email security features, and eligible organizations can obtain additional capabilities through Microsoft Defender for Office 365.
However, protections vary by subscription and configuration. Some enhanced security policies must be explicitly enabled and assigned to users. Microsoft Preset Security Policies in Cloud | Get Started With Microsoft Defender Office 365
No email-security system can guarantee that every phishing attempt will be stopped.
Do law firms need additional Microsoft 365 backup?
That depends on the firm's recovery objectives, retention requirements, licensing, and existing backup strategy.
Microsoft 365 offers several recovery and retention capabilities, but firms should verify whether those capabilities satisfy their specific requirements.
Additional Microsoft or third-party backup services may be appropriate.
How often should law firms review Microsoft 365 security?
There isn't one universal schedule.
However, firms should establish regular security reviews and reassess important settings following major technology changes, security incidents, significant staffing changes, or the introduction of new applications.
High-risk activities and security alerts may require continuous monitoring.
Can our existing IT provider perform a Microsoft 365 security assessment?
An IT provider with appropriate Microsoft 365 expertise and authorized administrative access can evaluate your environment.
A meaningful assessment should examine identity security, administrator permissions, email protection, data sharing, endpoint management, auditing, and recovery capabilities.
The assessment should also identify potential security gaps and provide recommendations appropriate for your firm's operations.
Don't Wait for a Security Incident to Review Your Microsoft 365 Environment
Your law firm relies on Microsoft 365 to communicate with clients, collaborate on documents, manage information, and keep everyday operations moving.
But using the technology and securing it properly are two different things.
A security review can help you understand where your firm stands, identify areas that need attention, and make informed decisions about protecting your information.
For North Texas law firms, this is particularly relevant as technology environments become increasingly connected and attorneys adopt new tools, including AI.
The question isn't whether your firm uses Microsoft 365.
It's whether your Microsoft 365 environment is configured to protect the information your firm depends on.
Is Your Law Firm's Microsoft 365 Environment Properly Secured?
Datatex Computer Services has been helping North Texas businesses manage their technology since 1975.
Our local team helps businesses manage their IT infrastructure, cybersecurity, Microsoft 365 environments, and data protection.
Whether your firm has an internal IT department, an existing technology provider, or needs comprehensive managed IT support, we're here to help you identify potential gaps and explore practical solutions.
Schedule a no-cost technology and security assessment with Datatex Computer Services.
Protect your firm's information before a security incident interrupts your business.
