For small firms holding privileged material
Your duty of confidentiality does not stop at the edge of your Microsoft 365 tenant.
Firms of five to twenty-five people, where the managing partner or the office administrator ended up owning IT by default — and where the tenant was set up to get email working, not to withstand a client security questionnaire.
The gap usually surfaces at the worst moment: a corporate client sends outside counsel guidelines, an insurer asks what controls are in place at renewal, or a wire goes to the wrong account.
What I find in firm tenants
Recurring findings in small firms running Microsoft 365 without a dedicated administrator.
The partners are the ones without MFA
Multi-factor authentication gets rolled out to staff and then quietly waived for the people who found the prompts disruptive — usually the partners. Those are the accounts holding the most sensitive client correspondence and the most authority to move money.
A departed associate still has access — and still has the files
The account was never disabled, so it still authenticates. Worse, if OneDrive or SharePoint was syncing to a personal laptop, the client files went out the door with them and nothing on your side recorded it.
Retention and legal hold are not a backup
Litigation hold preserves data against deletion for a matter. That is a different job from restoring a mailbox someone emptied, or a matter folder that ransomware encrypted and then synced to the cloud. Firms routinely assume hold covers both. It does not.
Auto-forwarding rules and wire instructions
A hidden mailbox rule copying inbound mail to an outside address is a standard step in business email compromise. For a firm handling real estate settlements or holding client funds, the next step is a fraudulent change to wire instructions sent from a mailbox that looks entirely legitimate.
Every user can open every matter
Most small firms run flat file storage — one drive, everyone in it. That makes need-to-know separation impossible to demonstrate, and it makes an ethical screen something you promise rather than something you can show was enforced.
The Microsoft 365 Security & Licensing Consultation
A guided working session. I look through the tenant with you and then write up what I found.
What it covers
- Identity and access — MFA coverage including partners, admin accounts, conditional access, legacy authentication.
- Account lifecycle — departed associates and staff, accounts with no current owner, offboarding and device sync.
- Mail flow — auto-forwarding and transport rules, external sharing, impersonation and spoofing protection.
- Matter separation — who can reach which files, and whether a screen could be evidenced if challenged.
- Data protection — what is retained, what is on hold, and what is actually recoverable.
- Licensing — what you are paying for, what is assigned, and what is going unused.
What you receive
A written findings report
Each finding in plain language: what it is, why it matters to a firm your size, and what remediation involves. Yours to keep, and written so you can hand it to a client, an insurer, or your own counsel.
A scored security posture
Where the tenant stands today across the areas above, so the answer to "how are we doing?" is a baseline rather than a guess.
A licensing waste analysis
Unassigned licences, duplicate paid features, and subscriptions still billing for people who have left. It frequently offsets the cost of the remediation work.
The terms, plainly
- No obligation. The report is yours whether or not we work together.
- No sales pitch. Reading the findings and going quiet is a normal outcome.
- No changes to your tenant. The consultation looks; it does not touch. Nothing is altered without your explicit go-ahead.
I am an IT consultant, not a lawyer. Nothing here is legal advice, and I do not opine on what your state’s rules of professional conduct require of your firm.
The work happens after your day ends
A firm cannot lose a working day to an IT project. Hours that are not billed are not recovered, and a calendar built around filing deadlines, closings, and court appearances has no slack in it to give.
So tenant changes, migrations, and cutovers are scheduled outside your working hours by default — not as a premium service, simply as how the work is organized.
All of it is administrative work inside Microsoft 365, delivered remotely. Nobody needs to be in your office, walking past files or sitting at a workstation.
Why it matters here specifically
The alternative to after-hours work is usually no work at all — the project slips another quarter, the questionnaire gets answered optimistically, and the gap stays open.
Questions firms ask
Does using Microsoft 365 satisfy my duty to protect client confidences?
Not on its own. The ABA Model Rules ask a lawyer to make reasonable efforts to prevent unauthorized access to or disclosure of information relating to a representation, and treat understanding the risks of relevant technology as part of competence. Most states have adopted some version of both; your own state’s rules of professional conduct govern. Microsoft 365 can be configured to support those obligations — the platform does not discharge them, and how your particular tenant is configured is the part that is actually yours.
Is a litigation hold the same as a backup?
No, and conflating them is common. A hold preserves data relevant to a matter against deletion. A backup exists so you can restore data after something goes wrong — an emptied mailbox, a ransomware event that encrypted files and then synced them, a site deleted past its retention window. A firm can be diligent about holds and still have no way to recover from any of those.
Can we use Copilot without exposing privileged material?
Only once matter separation is real. Copilot answers from whatever the person asking can already open, so a firm running flat file storage — one drive, everyone in it — gets a tool that will summarise a matter for someone screened off from it, on request, in seconds. The permissions were always that permissive; Copilot simply makes them easy to exercise. An ethical screen that exists as a policy rather than as an enforced permission does not survive contact with it. Get the separation enforced first, then Copilot becomes genuinely useful.
Our corporate clients send security questionnaires. Can you help with those?
Yes — that is one of the more common reasons firms call. Outside counsel guidelines and client security questionnaires tend to ask about MFA, access control, logging, encryption, backup, and incident response. The consultation produces the configuration detail and evidence those questions ask for. I do not complete the questionnaire on your behalf or advise on its legal terms.
What our clients say
Find out where your tenant actually stands
A written report you keep, and nothing in your tenant changes.
- No obligation — the report is yours either way.
- No sales pitch — the findings stand on their own.
- No changes are made to your tenant.