Law firms live in email and shared documents. One spoofed wire request, one hijacked mailbox, or one partner without MFA can become a client trust problem. We finish the basics so billable work stays in Outlook.
Most firms we see already live in Microsoft 365. Outlook, SharePoint, shared mailboxes, hybrid partners, and vendors sending as the firm are already in place. What’s missing is the unfinished basics. MFA is uneven, the domain can still be spoofed, and nobody owns who can send as the firm.
A firm that lives in Outlook
An 8–20 person law firm. Partners, paralegals, and a bookkeeper live in Outlook, SharePoint, and shared mailboxes. Outside counsel and vendors sometimes send as the firm. Work holds until a spoofed wire request looks real, a partner is locked out between hearings, or a client’s security questionnaire asks about MFA and nobody has a clean answer.
Security ambition, incomplete basics
Microsoft 365 is already in place, but MFA is uneven across partners and staff. Mail forwarding and “send as” nobody audited still exist. SPF, DKIM, and DMARC were never finished—or were set once and never reviewed after a migration—so a lookalike invoice can still land in a partner inbox.
The firm wants fewer ways for a fake settlement or vendor request to look legitimate. Partners cannot sit through a six-month security program. Someone has to answer the phone when MFA or Outlook blocks a hearing day.
Practical hardening, sequenced for a busy firm
We start with who can impersonate the firm and who gets locked out mid-matter—then sequence the rest around the calendar, not a product list.
Assessment
Review the tenant, partner and staff MFA, external sharing, and every mailbox or vendor that can send as the firm. You’ll get a short priority list—what’s urgent for client trust versus what can wait.
Email authentication
Put SPF, DKIM, and DMARC on a sensible path so spoofed mail is harder to pull off and legitimate tools still deliver. We use the same free checkers we publish so you can see progress yourself.
Partner and staff MFA
Turn MFA on for partners and admins, clean leftover forwarding, and tighten who can share a matter folder outside the firm.
Help between hearings
Same-day remote help when MFA or Outlook blocks a partner. Security work should not become a mid-matter fire drill.
Stay on it (optional)
A monthly plan if the firm wants someone watching the tenant after the records are in. Plenty of offices stop at the project.
Around the court calendar, not a six-month program
Who can send as the firm, who is missing MFA, and what a client questionnaire would actually ask.
Publish email authentication, roll MFA with help desk standing by, clean leftover forwarding.
Optional monthly watch on the tenant so the next hire or vendor does not undo the work.
What that looks like day to day
- ✓ A partner can answer a client’s MFA or email-security question without guessing.
- ✓ Lockouts go to help desk—not a colleague mid-deposition or after a flight.
- ✓ Email authentication is on a real path, not a record someone set two years ago.
A law firm’s reputation sits in email. The work is making spoofed wires and fake invoices harder to pull off—and keeping partners in Outlook when MFA or a shared mailbox gets in the way of billable time.
Common questions from firms
Will MFA disrupt partners?
We sequence MFA with support in place. Same-day help desk exists specifically so a locked partner isn’t stranded between hearings.
Do we need a full managed plan?
Not always. Plenty of firms start with email authentication and MFA, then decide later whether they want a monthly help desk. We’ll say which one fits this office.
Can we check our domain before we talk?
Yes. Use our free DMARC checker and spoof preview—no signup required.