Three Default Gaps That Create Direct Exposure
Depending on when your M365 plan was configured, you may still be dealing with these older, outdated basic-level gaps. While some newer configurations of the plan have amended these issues, if you've been working with Microsoft 365 for a long time, it would be a smart idea to double check these common issues:
- MFA not enforced: Microsoft 365 Security Defaults prompt for MFA but do not block access when MFA is bypassed; a stolen password alone can open every client matter in SharePoint.
- Legacy authentication enabled: Protocols like SMTP AUTH and Basic Auth bypass MFA entirely. Attackers target these specifically because they circumvent modern identity controls.
- No DLP policy: Without a Microsoft Purview Data Loss Prevention policy, an associate or paralegal can email a client's Social Security number or privileged communication to a personal Gmail account with no alert, no block, and no audit trail.
Six Security Settings to Configure
- Enforce MFA via Entra ID Conditional Access, not Security Defaults. Path: Microsoft Entra admin center → Protection → Conditional Access → New policy. Create a policy requiring MFA for all users, all apps. Security Defaults apply MFA inconsistently and cannot be scoped, a Conditional Access policy lets you require MFA everywhere while building a named exception for a specific courthouse kiosk scenario. Disable Security Defaults once Conditional Access is active to avoid overlap.
- Block legacy authentication protocols. Path: Entra admin center → Protection → Conditional Access → New policy → Conditions → Client apps → select Legacy authentication clients. Set Grant to ""Block access."" This disables SMTP AUTH and Basic Auth for all users, closing the MFA bypass that attackers rely on most.
- Enable Microsoft Purview sensitivity labels on SharePoint document libraries. Path: Microsoft Purview compliance portal → Information protection → Labels → Create a label, then SharePoint admin center → Settings → Enable sensitivity labels for SharePoint and OneDrive.
- Configure a Microsoft Purview DLP policy covering legal data types. Path: Microsoft Purview compliance portal → Data loss prevention → Policies → Create policy. Include sensitive information types: U.S. Social Security Number, U.S. Bank Account Number, and a custom keyword dictionary of privileged-communication markers. Set the policy to alert on internal sharing and block external sharing to non-approved domains.
- Enable Defender for Office 365 Safe Attachments and Safe Links firm-wide. Path: Microsoft 365 Defender portal → Email & collaboration → Policies & rules → Threat policies → Safe Attachments / Safe Links. Apply both policies to all recipients. Safe Attachments detonates email attachments in a sandbox before delivery; Safe Links rewrites and scans URLs at click time; both address the phishing vectors most commonly used against law firm staff.
- Set audit log retention. Path: Microsoft Purview compliance portal → Audit → Audit retention policies → New retention policy. Business Premium includes up to 180-day retention; set the policy explicitly rather than relying on the default, which may not be what your firm requires.
If configuring these settings in your own admin center isn't where you want to spend your billable hours, BroCoTec's IT support for Houston law firms covers the full implementation and ongoing monitoring of every item on this list.
Securing Remote Access and BYOD for Attorneys Working Outside the Office
Houston's legal market is courthouse-heavy. Attorneys access client files from home, from Harris County civil and criminal courthouses, and from client sites, often on personal iPhones. Microsoft Intune App Protection Policies and Entra ID Conditional Access location-based rules address this without requiring full device enrollment, which most attorneys at small firms will refuse.
Intune App Protection Policies for BYOD
Microsoft Intune App Protection Policies (a mobile application management feature in Intune) wrap the Outlook Mobile and Teams apps on a personal device with encryption, PIN requirements, and copy-paste restrictions, without enrolling or touching the personal device itself. An attorney at the Harris County courthouse can check client email on a personal iPhone; if that phone is lost, the firm can remotely wipe Outlook data without wiping the personal device.
Conditional Access Location-Based Policies
Entra ID Conditional Access supports named locations, defined IP ranges or geographic regions. Configure a policy involving pilot testing, report-only deployment and protected emergency-access accounts so step-up MFA doesn't lock out administrators. This flags anomalous access from unexpected geographies without blocking the attorney who legitimately works from a hotel or courthouse.
Azure AD Privileged Identity Management for Credential Theft Scenarios
Azure AD Privileged Identity Management (an additional license that is not included in base plans), a feature that requires just-in-time elevation for admin-level roles, prevents a stolen associate credential from becoming a full data exfiltration event. Without Privileged Identity Management, a compromised standard-user account that has been over-provisioned can access billing records, HR files, and all client matter libraries simultaneously. With Privileged Identity Management active, elevated access requires an additional approval step and is time-limited.
BroCoTec's cybersecurity services for Houston businesses include ongoing Conditional Access policy management and Intune app protection configuration as a monitored, managed layer, not a one-time setup.
Not Sure Your Firm's Microsoft 365 Tenant Is Actually Locked Down? BroCoTec Can Tell You in One Session.
BroCoTec's IT experts deliver plain-English findings with one quick discovery call so you can see how your firm's Microsoft 365 services stack up to cybersecurity requirements.
Book Your Discovery Call