An accounting firm should manage Microsoft 365 security through a layered approach that protects user identities, email, devices, administrative access, data, and recovery while continuously monitoring for changes and suspicious activity.

For a 5 to 25 employee accounting firm, a practical Microsoft 365 security program should include at least eight areas: Multi-Factor Authentication, Conditional Access, administrative-account protection, email security, device security, data protection, monitoring, and backup and recovery.

Simply having Microsoft 365 does not mean the environment is securely configured. Many important protections depend on how the tenant, identities, policies, permissions, devices, and administrative accounts are managed over time.

The objective is to make Microsoft 365 an actively managed part of the firm's cybersecurity program rather than a collection of settings configured once and rarely reviewed.

Why Is Microsoft 365 Security Important for Accounting Firms?

Microsoft 365 can sit at the center of an accounting firm's daily operations. Employees may use it for:

  • Email
  • Calendars
  • Microsoft Teams
  • OneDrive
  • SharePoint
  • File sharing
  • Microsoft Office applications
  • Identity and authentication
  • Access to other cloud applications

That makes a Microsoft 365 account valuable. If an attacker gains access to an employee's identity, the problem may extend beyond reading email. Depending on the account and configuration, unauthorized access could potentially be used to:

  • View business communications
  • Access files
  • Send messages as the employee
  • Create forwarding rules
  • Impersonate employees
  • Target clients or coworkers
  • Access connected applications
  • Change authentication settings

For an accounting firm handling sensitive financial and client information, Microsoft 365 should therefore be treated as business-critical infrastructure. Microsoft 365 protections should also operate as part of the firm's broader cybersecurity controls, particularly before tax season when email, identity, file access, and client communications can become especially important to daily operations.

An eight-part framework can help leadership evaluate how it is being protected.

1. Require Multi-Factor Authentication

Passwords alone should not be the primary barrier protecting Microsoft 365 accounts. Multi-Factor Authentication (MFA) adds another verification requirement when a user signs in. If an attacker obtains an employee's password through phishing, credential reuse, or another method, MFA can make that password alone insufficient to access the account. MFA should be part of a broader identity security strategy for the accounting firm that addresses passwords, authentication, access, and account management.

MFA Should Be Managed, Not Merely Enabled

A useful security review should ask:

  • Is MFA required for all appropriate users?
  • Are administrative accounts protected?
  • Which authentication methods are allowed?
  • Are legacy authentication methods still available?
  • What happens when an employee receives an unexpected MFA prompt?
  • How are lost or replaced phones handled?
  • Who can reset authentication methods?

The goal is not simply to check a box that says "MFA enabled." The firm should understand how authentication is configured and how exceptions are handled.

Employees Need to Understand Unexpected Prompts

Employees should know that an unexpected MFA request can be a warning sign. If an employee receives an authentication request they did not initiate, the procedure should not be simply: Deny it and continue working. The employee should know how to report the activity so the account can be investigated if necessary.

2. Use Conditional Access to Control How Accounts Are Used

MFA answers an important question: Can the user provide another authentication factor? Conditional Access can help answer additional questions about the circumstances of the login. Microsoft 365 security capabilities depend partly on licensing, configuration, and the firm's requirements. For firms evaluating Microsoft 365 Business Premium vs. Business Standard, security and device-management capabilities should be considered alongside productivity features and price. Depending on the available capabilities, Conditional Access policies may consider factors such as:

  • User identity
  • Administrative role
  • Device condition
  • Application
  • Location
  • Sign-in risk
  • Authentication method

This allows security requirements to reflect the circumstances of the access attempt rather than treating every login identically.

Avoid Creating Policies Without Understanding the Impact

Conditional Access is powerful, but poorly planned policies can also prevent legitimate users from working. Before deploying significant changes, understand:

  • Who will be affected?
  • Which applications are included?
  • Are emergency-access procedures available?
  • How will remote employees be affected?
  • What happens if a policy behaves unexpectedly?

Policies should be documented and tested before being broadly enforced.

Review Policies as the Firm Changes

A policy that made sense two years ago may not reflect the firm's current environment. Employees change. Applications change. Devices change. Microsoft capabilities change. Security requirements change. Conditional Access should therefore be treated as an ongoing management responsibility rather than a one-time implementation project.

3. Protect Administrative Accounts More Carefully

Administrative accounts deserve additional attention because they can change security settings, users, permissions, and other parts of the Microsoft 365 environment.

Start by asking: Who currently has administrative privileges?
Then ask: Does each person still need them?

A 20-person accounting firm should not accumulate administrators simply because giving someone additional access was convenient at some point.

Separate Administrative Work From Normal User Activity

Where appropriate, privileged administrative activity should be separated from normal email and day-to-day user activity. This can reduce the exposure of highly privileged credentials. The firm should also review:

  • Global administrator assignments
  • Other privileged roles
  • Third-party administrative access
  • MSP administrative access
  • Former employee accounts
  • Temporary administrative privileges
  • Emergency-access procedures

Review Your IT Provider's Access

If an MSP manages Microsoft 365, ask how its access is controlled. Questions include:

  • How do technicians authenticate?
  • How is privileged access assigned?
  • Is administrative activity logged?
  • How is access removed when a technician leaves?
  • How are emergency administrative actions handled?

The MSP may have significant access to the firm's environment. Protecting that access should be part of the firm's Microsoft 365 security strategy.

4. Strengthen Email Security

Email remains a common way for attackers to reach employees. Accounting firms may receive large numbers of messages involving:

  • Client documents
  • File-sharing notifications
  • Invoices
  • Banking information
  • Tax information
  • Password resets
  • Electronic signatures
  • Cloud applications

That creates opportunities for phishing and impersonation. Microsoft 365 email security should be evaluated for protections against threats such as:

  • Phishing
  • Malicious attachments
  • Malicious links
  • Spoofing
  • Impersonation
  • Unwanted forwarding
  • Suspicious mailbox activity

Protect the Business Process, Not Just the Inbox

Technical filtering cannot identify every fraudulent request. Accounting firms should also establish procedures for sensitive transactions. For example, employees may need an independent verification process before accepting:

  • Banking changes
  • Payment instructions
  • Direct-deposit changes
  • Requests for sensitive client information
  • Unusual account changes

A message can appear convincing even when technical controls are functioning. Security therefore needs both technology controls and employee procedures.

5. Secure the Devices Accessing Microsoft 365

Protecting Microsoft 365 accounts without protecting employee computers leaves an important gap. A compromised workstation can expose:

  • Active sessions
  • Stored files
  • Browser information
  • Credentials
  • Email
  • OneDrive data
  • Business applications

Employee devices should therefore be included in the Microsoft 365 security model. Depending on the firm's environment, device security may include:

  • Endpoint detection and response
  • Disk encryption
  • Patch management
  • Screen-lock policies
  • Device management
  • Local administrative-right restrictions
  • Supported operating systems
  • Security configuration standards

Account for Remote and Mobile Work

If employees work from home, travel, or use mobile devices, determine what access is appropriate outside the office.

Ask: Can unmanaged devices access business information? Can employees download files to personal devices? What happens when a company laptop is lost? How is access removed from a departed employee's device?

The answer will vary by firm. The important point is that these should be intentional decisions rather than accidental consequences of default settings.

6. Protect Microsoft 365 Data and Sharing

Security is not only about preventing unauthorized logins. The firm also needs to understand where information is stored and how it can be shared. Review:

  • OneDrive sharing
  • SharePoint permissions
  • External sharing
  • Guest users
  • Teams membership
  • Shared mailboxes
  • Distribution groups
  • File permissions
  • Retention requirements

Review External Sharing

Cloud collaboration makes sharing information easy. That convenience can also create long-lived access that nobody remembers. For example, a client, vendor, consultant, or former employee may have been given access to a SharePoint location for a legitimate project. Is that access still necessary six months later? A periodic access review can identify permissions that no longer reflect a business requirement.

Use the Principle of Least Privilege

Employees should generally receive the access necessary for their roles without receiving unnecessary access to unrelated information or administrative functions. As roles change, permissions should change with them. A documented IT onboarding and offboarding process helps ensure that Microsoft 365 accounts, permissions, devices, administrative privileges, and shared resources are updated as employees join, change roles, or leave the firm.

7. Monitor Microsoft 365 for Suspicious Activity and Configuration Changes

Security controls are more useful when someone is paying attention to what they report. Depending on the environment and licensing, monitoring may include:

  • Suspicious sign-ins
  • Authentication changes
  • Administrative activity
  • Security alerts
  • Mailbox forwarding
  • Inbox rules
  • Unusual access
  • Changes to privileged roles
  • Risky users
  • Device-security alerts

The key operational question is: Who reviews the alert, and what happens next?

An Alert Without a Response Process Is Incomplete

Suppose Microsoft 365 identifies unusual activity at 2:00 AM.

Ask: Who receives the alert? How quickly is it reviewed? What determines whether the account is disabled? Who investigates related activity? Who contacts the employee? When is leadership notified?

Monitoring should connect to a documented cybersecurity incident response plan that defines who reviews alerts, who can authorize containment, how incidents are escalated, and what happens when suspicious activity becomes a confirmed security incident. Otherwise, the firm may have valuable security information without an effective way to act on it.

8. Include Microsoft 365 in Backup and Recovery Planning

Cloud services provide resilience, but accounting firms should still determine what Microsoft 365 data needs to be protected and how it would be recovered. Depending on the firm's requirements, that may include:

  • Exchange Online email
  • OneDrive
  • SharePoint
  • Teams-related data

Leadership should understand:

  • What data is protected?
  • How frequently is it backed up?
  • How long is it retained?
  • Who monitors the backup?
  • How are restores performed?
  • Has recovery been tested?
  • What happens if an employee deletes important information?
  • What happens if malicious activity affects cloud data?

Do Not Assume Availability and Backup Are the Same Thing

Microsoft operating a highly available cloud platform does not eliminate the firm's responsibility to understand its data-protection and recovery requirements.

The useful question is not: "Is Microsoft 365 in the cloud?"
It is: "If we need to recover business information, what is our recovery process?"

That answer should be documented and periodically validated. The firm's broader backup and disaster recovery testing should verify not only that protected data exists, but that important business information can actually be restored when needed.

How Often Should an Accounting Firm Review Microsoft 365 Security?

Microsoft 365 security should not be reviewed only when a problem occurs. A practical approach can include:

Ongoing: Monitor security alerts and important events.

Monthly: Review operational security issues, unresolved alerts, and significant changes.

Quarterly: Review administrative access, security policies, sharing, licensing, and important recommendations. For firms using an MSP, these items can also become part of a structured quarterly review with the IT provider, along with unresolved risks, technology changes, recovery status, and priorities for the next quarter.

Annually: Conduct a broader Microsoft 365 security and identity review.

Additional reviews should occur when:

  • Employees join or leave
  • Administrative roles change
  • New applications are introduced
  • The firm changes IT providers
  • Microsoft licensing changes
  • A security incident occurs
  • Significant security features are deployed

The exact cadence should reflect the firm's environment and risk. The important point is that security configuration should not remain untouched for years.

A 15-Point Microsoft 365 Security Checklist for Accounting Firms

Leadership does not need to administer Microsoft 365 itself, but it should be able to obtain clear answers to these questions:

  1. Is MFA appropriately required for users?
  2. Are administrative accounts protected with stronger controls?
  3. Are Conditional Access policies documented and reviewed?
  4. Are unnecessary administrative privileges removed?
  5. Is MSP or third-party administrative access controlled?
  6. Are phishing, malicious links, attachments, and impersonation addressed?
  7. Are employee computers appropriately secured?
  8. Are unsupported devices or operating systems identified?
  9. Is external file sharing controlled and periodically reviewed?
  10. Are guest users and old permissions reviewed?
  11. Are suspicious sign-ins and security alerts monitored?
  12. Is there a defined response process for Microsoft 365 security incidents?
  13. Is important Microsoft 365 data included in the firm's recovery strategy?
  14. Has Microsoft 365 data recovery been tested where appropriate?
  15. Is Microsoft 365 security reviewed on a recurring schedule?

If several answers are unclear, that is itself useful information. It may indicate that Microsoft 365 is functioning as a productivity platform without being fully managed as part of the firm's cybersecurity environment.

Example: Reviewing Microsoft 365 Security for a 20-Person Accounting Firm

Consider a 20-person accounting firm that has used Microsoft 365 for several years. Email works. Employees use OneDrive. MFA is enabled. The firm has not experienced a significant Microsoft 365 incident. At first glance, the environment appears secure.

A structured review finds:

  • Two former administrators still have privileged roles.
  • Several employees have older authentication methods registered.
  • External SharePoint access from completed projects remains active.
  • A third-party application has permissions nobody has reviewed recently.
  • Employees are unsure what to do when they receive an unexpected MFA prompt.
  • Security alerts are generated, but ownership for reviewing some alerts is unclear.
  • Microsoft 365 recovery procedures have not been tested.

None of these findings means the environment has been compromised. They identify areas where security management has not kept pace with changes to the environment.

The firm creates a 60-day improvement plan:

First 15 days: Review administrative roles, authentication methods, and third-party access.

Days 16 to 30: Review Conditional Access, external sharing, and security-alert ownership.

Days 31 to 45: Update employee reporting procedures and Microsoft 365 security documentation.

Days 46 to 60: Validate backup and recovery procedures and establish a recurring review schedule.

The result is not simply "more security." The firm now has clearer ownership, configuration standards, monitoring, and verification.

Who Should Be Responsible for Microsoft 365 Security?

Responsibility should be explicit. Depending on the firm's operating model, Microsoft 365 may involve:

Firm leadership: Defines business requirements, risk tolerance, and access expectations.

Employees: Follow security procedures and report suspicious activity.

Internal IT: Administers accounts, devices, applications, and policies.

Managed IT provider: May manage security configuration, monitoring, identity, devices, recovery, and escalation.

Specialized cybersecurity resources: May provide additional assessment, monitoring, or incident-response capabilities.

The exact model matters less than whether everyone knows who owns each responsibility. One of the most dangerous assumptions is: "We thought someone else was managing that."

Microsoft 365 Security Is an Ongoing Operating Process

There is no single Microsoft 365 setting that makes an accounting firm secure. Security depends on multiple layers working together:

Identity: Who is signing in?

Authentication: How is identity verified?

Access: What can the user reach?

Device: Is the endpoint appropriately protected?

Email: How are phishing and impersonation addressed?

Data: Where is information stored and shared?

Monitoring: Who is watching for suspicious activity?

Recovery: What happens when something goes wrong?

Those layers also change as the firm changes. That is why Microsoft 365 security should be managed as an operating process rather than a one-time configuration project.

How Everleap IT Approaches Microsoft 365 Security

Everleap IT's approach has been shaped by more than 20 years of operating production hosting environments, where identity, access, monitoring, security, documentation, and recovery all contribute to operational reliability.

For accounting firms, those principles can be applied through:

  • Microsoft 365 administration
  • Multi-Factor Authentication
  • Conditional Access
  • Identity and access management
  • Email security
  • Endpoint security
  • Administrative-access management
  • Proactive monitoring
  • Backup and recovery
  • IT documentation
  • Security reviews
  • Production Readiness assessments

The objective is not simply to turn on more security features. It is to establish a repeatable process for configuring, monitoring, reviewing, and improving Microsoft 365 security over time.

Is Your Accounting Firm Managing Microsoft 365 Security or Just Using Microsoft 365?

Start with eight areas:

  1. Multi-Factor Authentication
  2. Conditional Access
  3. Administrative access
  4. Email security
  5. Device security
  6. Data and sharing
  7. Monitoring and incident response
  8. Backup and recovery

Then ask one additional question: Who is responsible for each one?

If the answer is unclear, the firm may have a Microsoft 365 responsibility gap even if email, Teams, and OneDrive are working normally.

Everleap IT helps accounting firms throughout California's Inland Empire, including Rancho Cucamonga, Upland, Ontario, Claremont, and nearby communities, protect and operate business-critical technology through Microsoft 365 administration, cybersecurity, identity management, proactive monitoring, backup and recovery, documentation, strategic planning, and Production Readiness assessments.

If your accounting firm wants a clearer picture of its Microsoft 365 security posture, a technology assessment can help identify configuration, identity, access, monitoring, device, and recovery gaps and prioritize the areas that should be addressed first. We are always here to chat about your IT needs and set up a technology assessment.