Skip to main content
Kumonix - Microsoft Solutions Partner
All articles

The M365 Security Settings Your IT Team Probably Hasn't Turned On

Most law and professional services firms have MFA switched on but Conditional Access, the setting that actually decides who gets in, usually isn't configured

Kumonix Team 8 min read

If you asked your IT team right now "are we secure?", they'd probably say yes. MFA's on. Passwords are enforced. Boxes are ticked.

But ask a follow-up question, "what happens if someone's password gets phished tonight?", and the answer gets a lot less confident.

That gap is where most breaches actually happen. Not because MFA failed, but because MFA was the only thing standing in the way, and it wasn't backed up by anything smarter behind it.

The setting that closes that gap is called Conditional Access. It sits inside Microsoft Entra ID (the identity and access part of Microsoft 365), and in nearly every tenant we look at, it's either unconfigured or left on Microsoft's defaults. That's not a criticism of any one firm, it's just what happens when a rollout focuses on getting everyone working, and security configuration gets left as a "we'll come back to it" item that never quite gets revisited.

Here's what it is, why it matters for firms handling client data, and what to actually do about it.

What Conditional Access Actually Does

MFA asks one question: "prove it's you." It asks that question the same way every time, whether you're logging in from your desk on a company laptop, or from an unfamiliar device in a country your firm has never done business in.

Conditional Access adds context to that question. It lets you set rules like:

  • Block sign-ins from outside the countries you operate in Require a managed, compliant device before anyone can access client files
  • Trigger extra verification for anything that looks unusual, a new device, an unfamiliar location, an odd time of day
  • Block older, insecure sign-in methods that don't support modern authentication at all

Many of the most valuable Conditional Access controls are already available within Microsoft 365 Business Premium and Enterprise licensing, yet remain unused.

The Hidden Risk Most Firms Never Check

While we're talking about access controls, there's another issue that's worth mentioning: legacy authentication.

These are older sign-in protocols used by outdated applications and devices. The problem is that many of them don't support modern security controls such as MFA or Conditional Access in the way you'd expect.

In practice, that means a firm can spend time rolling out MFA, only to leave an alternative route into Microsoft 365 that bypasses many of those protections altogether.

The good news is that blocking legacy authentication is usually one of the simplest and highest-impact Conditional Access policies to implement. For most firms, it's a quick win that closes off an attack path they didn't realise was still open.

Why This Matters More For Law Firms and Professional Services

Firms handling client data (legal, accounting, financial advisory) carry a different level of risk than a typical SMB. A compromised mailbox isn't just an inconvenience. It's a potential client confidentiality breach, a regulatory reporting obligation, and in the legal sector, a direct line to your SRA obligations around safeguarding client information.

The SRA's cyber security guidance is explicit that firms need to understand where their risks actually sit, not just that "cyber security" as a general concept has been addressed. A firm that can say "we have MFA" but can't explain what happens after that point hasn't really answered the question.

What Happens When It's Missing

Picture the most common attack path: a user's credentials are compromised through phishing, token theft, or an MFA approval they didn't properly scrutinise. The attacker now has enough information to attempt access as that user.

With no Conditional Access in place, that's the end of the story. The attacker's in. Same access as the real user, no extra checks, no flag raised.

With Conditional Access configured properly, that same phished login gets stopped or challenged again because it's coming from an unrecognised device, or a location the policy doesn't trust, or it fails a device compliance check. The MFA approval alone isn't enough to get through.

That's the entire value of the setting: it assumes the first line of defence might fail, and gives you a second one that doesn't rely on a stressed employee making the right call in the moment.

What Getting This Right Actually Looks Like

Conditional Access isn't a single switch, it's a set of policies that need to reflect how your firm actually works. Getting it right generally means:

  • Start with the basics. Block legacy authentication protocols outright, they don't support modern security checks and are a common entry point. Require MFA for every user, no exceptions for partners or senior staff (we still routinely find MFA switched off for the most senior people in a firm, usually because it was "too disruptive" to set up early on)
  • Layer in risk-based rules. Not every login needs the same level of scrutiny. A partner accessing client files from an unmanaged personal laptop is a different risk profile to someone on a company device in the office. Policies should reflect that difference
  • Test before you enforce. Conditional Access supports a report-only mode, it shows you who would be blocked by a policy before it actually blocks anyone. This is the difference between rolling out security improvements smoothly and locking out half the partners on a Monday morning
  • Review it regularly. Staff change roles. New starters join. Devices get replaced. A policy set once during onboarding and never looked at again drifts out of date, and drift is exactly where gaps reappear

Where to Start

You don't need to rebuild your entire security setup this week. Start with one question: does anyone at your firm actually know what your current Conditional Access policies do not whether MFA is "on," but what rules are actually governing access?

If the honest answer is "not really," that's the starting point, not a failure. It's the single most common gap we come across, and it's usually fixable without disrupting how your team works day to day.

If you're not sure what your current Conditional Access policies do, that's exactly where an assessment starts. In most cases, we can identify meaningful security improvements in under an hour simply by reviewing the policies already sitting inside Entra ID.

Next article

Microsoft's MFA Mandate Doesn't Cover Your Fee Earners

Read the next article

Ready to transform your business?

Let's discuss how our Microsoft solutions can drive your business forward. Get a free consultation and discover what's possible.