
Your law firm has Microsoft 365.
Your employees have passwords. Your attorneys use multifactor authentication. Your files are stored in SharePoint or OneDrive, and your email is protected by Microsoft's security technology.
Everything sounds secure.
But here's a question worth asking:
When was the last time someone actually verified that your firm's Microsoft 365 security settings were configured correctly?
For many law firms, there's a significant difference between having security tools and knowing those tools are working as intended.
Microsoft 365 offers powerful security capabilities. However, the protection your firm receives depends on its subscription, configuration, security policies, employee behavior, and ongoing management.
A security feature that's included but never configured may provide little protection against the threats it was intended to address.
For North Texas law firms handling confidential client information, financial transactions, discovery materials, and sensitive communications, that distinction matters.
A Microsoft 365 security assessment helps your firm understand where it stands.
And sometimes, what you discover may surprise you.
For more information, our blog "Microsoft 365 Security for Law Firms" has 10 Microsoft 365 security settings checklist.
What Is a Microsoft 365 Security Assessment?
A Microsoft 365 security assessment is a structured review of your organization's Microsoft 365 environment to identify security weaknesses, configuration issues, unnecessary permissions, and opportunities to improve data protection.
Depending on the firm's technology environment and licensing, an assessment may examine:
- User accounts and multifactor authentication
- Administrative privileges and identity protection
- Email security and phishing defenses
- SharePoint, Teams, and OneDrive permissions
- External sharing and guest access
- Device security and remote access
- Data loss prevention and sensitive information protection
- Audit logging and security monitoring
- Backup and recovery capabilities
- Third-party application access
The objective isn't simply to produce a list of technical problems.
It's to identify risks that could affect your firm's ability to protect client information, maintain operations, and respond to security incidents.
An effective assessment should translate technical findings into business decisions your leadership team can understand.
Why Law Firms Shouldn't Assume Microsoft 365 Is Secure by Default
Microsoft provides numerous security capabilities, but some protections require additional licensing, configuration, or administrative action.
For example, Microsoft Entra Conditional Access provides controls that can restrict access based on factors such as user identity, device compliance, and other supported conditions. However, Conditional Access requires appropriate licensing and must be configured to match your organization's needs.
Microsoft also offers security defaults for organizations seeking baseline identity protection. Security defaults and Conditional Access are different approaches, so your IT provider should determine which is appropriate for your environment.
Get Started with Defender for Office 365 | Preset Security Policies in Cloud Organizations
This creates an important distinction.
Your law firm may own the necessary security technology without having fully implemented it.
Or you may have implemented protections several years ago that no longer reflect your current staffing, workflows, and security requirements.
A security assessment can help identify those gaps.
7 Warning Signs Your Law Firm May Need a Microsoft 365 Security Assessment
1. Nobody Knows Who Has Administrative Access
Think about the people who have managed your firm's technology over the years.
Perhaps you've changed IT providers, hired an internal IT employee, worked with consultants, or added new software vendors.
Do you know which accounts currently have administrator privileges?
Administrative accounts can control important security settings, manage users, and perform other privileged activities.
Excessive administrative permissions can increase the consequences of a compromised account.
Your firm should be able to identify its privileged accounts, explain why each one exists, and confirm that appropriate safeguards are in place.
If nobody can provide that information, an administrative-access review is a sensible starting point.
2. Your Firm Has MFA, but Nobody Has Verified Its Coverage
Multifactor authentication is one of the most important protections available for business accounts.
However, simply enabling MFA doesn't guarantee that every account is adequately protected.
Your firm may have older accounts, service accounts, authentication exceptions, or inconsistent policies.
Some authentication methods also offer stronger protection against phishing than others.
A security assessment should examine your authentication policies, identify exceptions, and determine whether privileged accounts have appropriate protection.
The question isn't simply whether your firm uses MFA. It's whether the right protections apply to the right accounts.
3. Employees Have Accumulated Access to Files They No Longer Need

Imagine an employee who joined your firm five years ago.
They've changed positions twice, worked with several practice groups, and participated in numerous client matters.
Over time, they may have accumulated access to SharePoint sites, Teams channels, shared folders, and other information repositories.
But has anyone reviewed those permissions?
Microsoft 365 provides tools for managing access, but your firm remains responsible for assigning and reviewing permissions appropriately.
This is especially important when introducing AI tools such as Microsoft 365 Copilot.
AI applications that respect existing user permissions may make information easier to discover. If permissions are too broad, employees may discover information they shouldn't need for their current responsibilities.
Your security assessment should identify unnecessary access and recommend a process for reviewing permissions regularly.
For additional context, see our articles Your Attorneys Are Already Using AI. Does Your Law Firm Know Where the Data Is Going? and Should Your Law Firm Have an AI Acceptable Use Policy?
4. Your IT Provider Has Never Reviewed External File Sharing
Law firms regularly collaborate with outside parties.
Attorneys share documents with clients, expert witnesses, outside counsel, consultants, and other professionals.
Microsoft 365 makes this collaboration convenient.
However, external sharing should be governed by appropriate security controls.
A security assessment should examine whether your organization permits anonymous sharing links, how guest access is managed, whether sharing permissions are appropriately restricted, and whether external access is reviewed.
Consider asking your IT provider:
Could someone outside our firm still access documents from a matter that closed two years ago?
The answer may depend on how your environment was configured and whether access has been reviewed.
5. Your Firm Doesn't Know Whether Its Email Security Is Fully Configured
Your attorneys exchange sensitive information through email every day.
A successful email compromise could expose confidential correspondence, create opportunities for financial fraud, or disrupt important communications.
Microsoft 365 provides baseline email protections, with additional capabilities available through eligible Microsoft Defender for Office 365 subscriptions.
However, your firm should verify that the protections available under its licensing are appropriately configured.
An assessment may examine anti-phishing policies, impersonation protection, malicious-link detection, attachment protection, external forwarding, and email-domain authentication.
It should also examine how suspicious activity is identified and investigated.
6. Your Firm Has Backups but Hasn't Tested Recovery
"We have backups."
That's a reassuring statement.
But can your firm demonstrate that its critical information can actually be recovered?
Microsoft 365 includes various data protection, retention, and recovery capabilities, but those features don't automatically satisfy every organization's recovery requirements.
A security assessment should examine your existing backup strategy, identify which Microsoft 365 services are covered, and determine whether recovery procedures have been tested.
The goal is to answer practical questions.
How much information could your firm lose during a disruption?
How quickly could important email and documents be restored?
Who would coordinate the recovery?
A backup strategy should reflect your firm's business continuity requirements, not simply the features included in your subscription.
7. Your Firm Has Never Received a Written Security Assessment
Your IT provider may be doing an excellent job managing everyday technology issues.
But ongoing IT support and a documented security assessment aren't necessarily the same thing.
A meaningful assessment should provide more than a verbal assurance that everything looks fine.
It should identify the areas reviewed, document relevant findings, explain potential business implications, and recommend appropriate next steps.
Your leadership team should understand which issues require immediate attention, which improvements can be planned, and which risks have been consciously accepted.
If your firm has never received that information, it may be time to request a structured review.
What Should a Microsoft 365 Security Assessment Include?
A comprehensive assessment should go beyond checking whether individual security features are enabled.
It should evaluate how those protections work together and whether they meet your firm's actual business needs.
The 5 Essential Areas to Assess
- Identity and access security
Review MFA, administrator privileges, inactive accounts, authentication policies, and employee access. - Email and collaboration security
Examine phishing protection, external email forwarding, SharePoint permissions, Teams collaboration, and OneDrive sharing. - Data protection and recovery
Evaluate sensitive information protection, retention policies, backups, and tested recovery procedures. - Devices and applications
Identify unmanaged devices, outdated applications, third-party integrations, and inappropriate application permissions. - Monitoring and incident response
Verify audit logging, security alerts, investigation procedures, and your firm's ability to respond to suspicious activity.
For example, Microsoft Purview provides auditing capabilities, but audit availability and retention depend on licensing and configuration. An assessment should verify that the firm is collecting and retaining the records it needs rather than assuming those records will always be available.
Turn Auditing On or Off | Manage Audit Log Retention Policies
What Is Microsoft Secure Score, and Should Your Law Firm Use It?
Microsoft Secure Score is a tool that helps organizations evaluate their Microsoft security configurations and identify recommended improvements.
It provides visibility into security measures involving identities, devices, applications, and data.
However, Secure Score isn't a certification, a guarantee against cyberattacks, or a complete security assessment.
Microsoft specifically cautions that the score should not be interpreted as a measurement of an organization's absolute likelihood of experiencing a security breach.
Assess Your Security Posture with Microsoft Secure Score | Microsoft Secure Score
For law firms, Secure Score can provide a useful starting point.
Your IT provider can use its recommendations alongside configuration reviews, vulnerability assessments, access reviews, and discussions about your firm's operational requirements.
The objective shouldn't be to chase a particular number.
It should be to understand and address meaningful security risks.
What Should You Receive After a Microsoft 365 Security Assessment?
A security assessment should provide your leadership team with actionable information.
At minimum, request a written report containing:
- Executive summary: A plain-English explanation of the assessment's findings.
- Scope: Which systems, accounts, and security controls were reviewed.
- Identified gaps: Security weaknesses, misconfigurations, or areas requiring additional investigation.
- Business implications: How the findings could affect confidentiality, productivity, or business continuity.
- Recommended improvements: Practical steps for addressing the identified issues.
- Implementation plan: Suggested priorities, responsibilities, and follow-up actions.
Your report should also identify important limitations, including systems that weren't assessed or protections that couldn't be evaluated because of licensing or access restrictions.
This helps your firm distinguish verified findings from areas that still require investigation.
How Often Should a Law Firm Assess Its Microsoft 365 Security?
There isn't a single assessment schedule appropriate for every firm.
However, law firms should establish regular reviews based on their security risks, client requirements, technology environment, and business operations.
Additional assessments may be appropriate when your firm changes IT providers, experiences significant growth, introduces new applications, expands remote work, implements AI, or experiences a security incident.
Certain activities, such as monitoring suspicious sign-ins and responding to critical security alerts, may require continuous attention rather than periodic reviews.
A security assessment should be part of an ongoing cybersecurity program, not an activity performed once and forgotten.
Frequently Asked Questions About Microsoft 365 Security Assessments
Is a Microsoft 365 security assessment the same as a cybersecurity audit?
Not necessarily. A Microsoft 365 security assessment focuses on the security configuration and operation of your Microsoft 365 environment.
A broader cybersecurity audit may include additional infrastructure, applications, physical security, policies, employee practices, and compliance requirements.
The terms are sometimes used interchangeably, so always confirm the scope of the proposed service.
Check out our blog, Cybersecurity Requirements Every Texas Law Firm Should Know in 2026, for more information.
Can a law firm perform its own Microsoft 365 security assessment?
Yes, if it has personnel with the necessary expertise and authorized access.
However, an independent assessment may provide additional perspective, particularly when your firm has limited internal IT resources or hasn't reviewed its environment recently.
Will a Microsoft 365 security assessment interrupt our firm's operations?
A configuration-focused assessment can often be performed with minimal disruption.
However, some testing or remediation activities may require additional planning.
Your IT provider should explain the assessment's scope, obtain appropriate authorization, and coordinate potentially disruptive activities.
Does a Microsoft 365 security assessment help prepare a law firm for AI?
Yes. Reviewing identity management, data permissions, external sharing, and information protection can help identify existing weaknesses before connecting AI applications to organizational information.
However, a Microsoft 365 assessment doesn't replace a separate evaluation of an AI application's security, privacy, and data-handling practices.
How much does a Microsoft 365 security assessment cost?
Pricing depends on the number of users, complexity of the environment, licensing, assessment scope, and whether remediation is included.
Some IT providers offer an initial assessment at no cost, while more extensive security audits and remediation projects may involve additional fees.
Ask for a clearly defined scope before proceeding.
Is Your Law Firm Confident in Its Microsoft 365 Security?
You don't need to understand every Microsoft 365 setting to lead a law firm effectively.
But you should know whether someone with the appropriate expertise has reviewed those settings and verified that your firm's important information is appropriately protected.
You should also know what happens when something goes wrong.
For North Texas law firms, a Microsoft 365 security assessment can provide a clearer understanding of existing protections, potential weaknesses, and opportunities for improvement.
Find Out Where Your Law Firm Stands
Datatex Computer Services has helped North Texas businesses manage their technology since 1975.
Our local team provides managed IT, co-managed IT, cybersecurity, Microsoft 365 support, and data backup and recovery services.
Whether your law firm has an internal IT department or relies on an outside provider, we can help you take a closer look at your technology environment.
Schedule a no-cost technology and security assessment with Datatex Computer Services.
Protect your firm's information. Reduce unnecessary risks. Get clear answers without the geek-speak.
This article provides general technology and cybersecurity information. It is not legal advice or a guarantee of security or regulatory compliance.
