Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Resources2026-09-22By Securing Your Law Firm

Microsoft 365 Security Checklist for Small Law Firms

Use a business-focused Microsoft 365 security checklist to verify sign-ins, access, sharing, forwarding, logging, and recovery evidence.

Your Firm Uses Microsoft 365. Which Safeguards Have Been Verified?

Blog post - By Securing Your Law Firm

Buying Microsoft 365 or enabling a feature is not evidence that every safeguard is configured, in scope, or operating as intended. A tenant can be a strong platform and still need an authorized review.

This checklist is a decision aid, not a claim about your tenant and not a substitute for current Microsoft documentation. Licensing, configuration, third-party services, retention, and scope change what can be checked.

Verify the outcomes that matter

Protect sign-ins

Why leadership should care: a stolen password should not be enough to reach client work. Evidence: identity policies, MFA scope, administrative exceptions, and recent sign-in protection evidence. Limitation: a settings review does not prove that every social-engineering attempt will fail.

Limit administrative access

Why: excessive privilege increases the impact of one compromised account. Evidence: administrator inventory, role assignments, emergency-access documentation, and review dates. Limitation: role evidence is a point-in-time view and depends on complete tenant scope.

Remove former-user access

Why: departures create avoidable access and data-retention risk. Evidence: joiner/leaver procedure, recent revocation record, session/token handling, and mailbox or file ownership review. Limitation: off-platform copies and personal devices require separate scope.

Review sharing of matter files

Why: a convenient external link can expose confidential work beyond the intended audience. Evidence: SharePoint/OneDrive sharing settings, representative site permissions, guest access, and review records. Limitation: a sample cannot represent every matter site unless the scope says it does.

Identify forwarding and mailbox risks

Why: unauthorized forwarding can quietly disclose mail. Evidence: mailbox rules, external forwarding configuration, transport rules, and alerting. Limitation: this requires authorized access and does not prove that a legitimate account has not been misused in another way.

Retain useful logs

Why: an incident response starts with what the firm can reconstruct. Evidence: audit-log settings, retention period, alert ownership, and a recent retrieval example. Limitation: licensing and retention choices affect history and availability.

Establish recovery evidence

Why: recovery plans matter only when the firm can restore what it needs. Evidence: backup scope, recovery objectives, dated restoration test, and ownership. Limitation: Microsoft 365 retention or recycle features are not automatically a complete backup strategy.

An illustrative finding layout

| Field | Example | | --- | --- | | Observation | External sharing is allowed for selected matter sites | | Supporting evidence | Setting, affected site scope, and review date | | Affected scope | Three sites reviewed; firm-wide coverage not established | | Priority | High because client files are shared externally | | Recommended action | Confirm approved sharing model and review guest access | | Verification status | Partially verified |

This format separates an observation from a conclusion. It gives leadership and an IT provider something specific to act on without presenting invented tenant results.

What an authorized review can cover

The Law Firm Security Baseline reviews agreed Microsoft 365 identity, access, email, and evidence areas. Email & Microsoft 365 Security can address scoped mailbox and domain work. Broader permissions redesign, DLP, sensitivity labels, ethical walls, recovery engineering, and implementation may need separate scope.

The service uses authorized access or evidence. The Free Zero-Access Exposure Review™ is a public check only; it is not a Microsoft 365 configuration audit.

A small-firm review sequence

Start with the business event: a departed employee, unexpected external sharing, a mailbox-forwarding concern, a client questionnaire, or a planned migration. Confirm the tenant, users, sites, domains, licenses, and third-party services in scope. Then request evidence, classify what was observed, and agree which changes need an implementation proposal.

Microsoft’s current documentation should be checked before relying on a named feature or license-dependent control. Avoid treating a portal screenshot as proof that the control operates across the whole firm.

Choose the right next step

For a decision-ready review, request the applicable authorized assessment. For a public starting point, use the exposure review. For configuration changes, state the desired outcome and tenant scope so the work can be priced and authorized accurately.

This article is for informational purposes only and does not constitute legal, compliance, or insurance advice.