You’re paying for Microsoft 365. You’re probably not getting what you paid for.
Most Chicago law firms are running Microsoft 365. It’s become the default platform for email, calendars, Teams, document storage, and collaboration. For firms that migrated from on-premise Exchange or legacy systems, the improvements were immediate and noticeable.
What’s less visible is what the out-of-the-box configuration doesn’t provide.
Microsoft 365, in its default state, is a productivity platform. It is not automatically a compliance solution, a data protection system, or a complete security architecture. The capabilities that make it those things — Data Loss Prevention (DLP), retention policies, conditional access, audit logging, and advanced security controls — exist within the platform, but they must be configured properly.
In our experience assessing Chicago law firms, these features are rarely configured correctly.
What most firms have is a Microsoft 365 environment that sends and receives email, stores files in OneDrive, and hosts Teams meetings. What most firms believe they have is a secure and compliant legal technology environment. The gap between those two realities is significant.
What Microsoft 365 Provides Out of the Box
A standard Microsoft 365 deployment includes:
- Exchange Online for email
- Calendars and contacts
- Microsoft Teams for chat and video meetings
- OneDrive for personal file storage
- SharePoint for document libraries
- Microsoft Office applications
What it does not provide by default includes:
- Data Loss Prevention policies
- Retention and records management policies
- Mandatory Multi-Factor Authentication (MFA)
- Conditional access restrictions
- External sharing controls
- Advanced audit logging and reporting
For law firms, these missing configurations create risks that translate directly into confidentiality concerns, compliance exposure, and potential malpractice liability.
The Five Most Common Microsoft 365 Gaps We Find in Chicago Law Firms
No Data Loss Prevention on Email
Email DLP policies allow firms to control what information can leave the organization.
A properly configured policy can identify and block messages containing client file numbers, Social Security numbers, financial account information, or other sensitive data before they are sent externally.
Without DLP, there is no automated safeguard preventing an attorney or staff member from accidentally sending confidential information to the wrong recipient.
Client Files Stored in Personal OneDrive Accounts
Many attorneys save client files to their personal OneDrive because it is convenient.
The problem is that personal storage creates long-term management issues. If an attorney leaves the firm, retires, or becomes unavailable, access to those files can become difficult or impossible.
SharePoint provides better governance, stronger access controls, version history, and centralized management. Yet many firms continue to rely heavily on individual OneDrive accounts for client data.
Multi-Factor Authentication Is Not Enforced
Microsoft 365 supports MFA, but support and enforcement are not the same thing.
In many environments, MFA is optional or applied only to certain users. That leaves individual accounts vulnerable to phishing attacks and credential theft.
One compromised attorney account can provide access to email, documents, Teams conversations, and client information across the firm.
No Controls on Teams External Sharing
Microsoft Teams makes collaboration easy, but without proper controls it can also create unnecessary risk.
By default, users can invite external guests and share files outside the organization. Without approval workflows and restrictions, sensitive information can be shared unintentionally with the wrong people.
For law firms handling confidential matters, unmanaged external sharing introduces avoidable exposure.
No Retention Policy for Client Communications
Many firms have never formally answered a basic question:
How long should client communications be retained?
Without retention policies, the answer often becomes whatever individual attorneys decide to do with their inboxes.
A defensible retention strategy ensures that communications and documents are preserved appropriately, remain discoverable when necessary, and are managed consistently across the organization.
What Proper Microsoft 365 Configuration Looks Like for a Law Firm
A properly configured legal Microsoft 365 environment typically includes:
- Data Loss Prevention policies tailored to legal workflows
- SharePoint document libraries with matter-based permissions
- Firm-wide Multi-Factor Authentication enforcement
- Controlled external sharing within Teams and SharePoint
- Retention policies aligned with firm requirements
- Unified audit logging and monitoring
- Conditional access policies restricting risky logins
- Security baselines for attorneys and staff
These controls work together to create an environment that supports both productivity and compliance.
Importantly, this is not a one-time project.
Microsoft 365 evolves continuously, firm requirements change, and new security threats emerge. Maintaining a secure environment requires ongoing management and periodic review.
How Microsoft 365 Supports Legal Compliance
ABA Model Rule 1.6(c) requires attorneys to make reasonable efforts to prevent unauthorized disclosure of client information.
The rule specifically considers factors such as:
- The sensitivity of the information
- The likelihood of disclosure
- The cost and difficulty of implementing safeguards
A properly configured Microsoft 365 environment demonstrates reasonable effort through documented security controls, access management, auditing, and data protection policies.
As cyber insurance carriers, clients, and regulators increasingly evaluate technology practices, these controls become more than best practices — they become evidence of due diligence.
How CMIT Chicago Helps Law Firms Secure Microsoft 365
CMIT Chicago provides Microsoft 365 assessment, configuration, security management, and ongoing support for Chicago law firms.
We begin with a comprehensive Microsoft 365 review that evaluates your current environment against a legal-industry security baseline. From there, we help implement the controls that matter most for your firm, practice areas, and compliance requirements.
More importantly, we continue managing the environment as Microsoft evolves and your firm’s needs change.
Because Microsoft 365 security is not a one-time project.
It’s an ongoing commitment to protecting client information, supporting compliance, and maintaining a technology environment your attorneys can trust.