Microsoft's MFA Mandate Doesn't Cover Your Fee Earners
Microsoft now enforces MFA for every admin account, but many staff may remain exposed. Learn how law firms can identify the gap and strengthen protection.
If you've heard your IT team or IT provider mention Microsoft's MFA mandate recently, you might reasonably assume your firm's accounts are now protected by multi-factor authentication. Microsoft made it compulsory, after all. Box ticked.
Here's the uncomfortable part: the mandate almost certainly doesn't cover the people in your firm who matter most.
Microsoft's enforcement, which finished rolling out earlier this year, with the final extensions expiring in July 2026, applies to administrative access. The portals your IT team uses to manage users, licenses and settings now require MFA, full stop. That's a genuinely good change. Admin accounts are the keys to the whole building, and password-only admin access should have died years ago.
But your fee earners, your accounts team, your secretaries, your partners, the people who actually hold client correspondence, matter files and client money, are not covered by the mandate. Nothing Microsoft has enforced stops them signing in with just a password. If your firm hasn't deliberately configured MFA for all users, it isn't there.
And in the tenants we review, it very often isn't there. Or it's half there, which is arguably worse, because everyone believes the job is done.
Why this matters more for law firms than almost anyone else
Every business has something to lose from a compromised mailbox. Law firms have more.
A single fee earner's mailbox typically contains privileged correspondence, drafts, financial details, and, critically, the email threads where bank details and completion instructions get exchanged. Payment diversion fraud against conveyancing transactions remains one of the most reliably profitable attacks in the UK, and it almost always starts the same way: someone gets into a mailbox, reads quietly for a few weeks, then sends a well-timed email changing the account details.
The SRA has been clear for years that firms are expected to take proportionate steps to protect client information and client money, and that "we didn't know the setting existed" is not a proportionate step. If a breach investigation finds that your fee earners could sign in with a password alone in 2026, that is a difficult conversation, with the SRA, with your insurer, and with the client whose money went missing.
MFA doesn't make you unbreachable. It does remove the cheapest, most common way in. Microsoft's own research puts the reduction in account compromise risk from MFA at over 99%. Very few security controls give you that much for that little.
The gaps we find most often
When we review M365 environments, the same handful of issues come up again and again:
Partial MFA coverage. MFA was rolled out at some point, but with exceptions. A partner who found it irritating. A shared mailbox that someone licensed as a normal account. A "temporary" exclusion from 2022 that became permanent because nobody owned the follow-up. Attackers don't need everyone to be unprotected, they just need one account.
Legacy authentication still enabled. Older protocols, the ones used by ancient mail apps, some scanners and old line-of-business software, don't support MFA at all. If they're not blocked, an attacker can authenticate through them with just a username and password, and your MFA policy never even gets asked. This is the single most common serious gap we see, and it's invisible in day-to-day use because everything still works.
MFA via text message for senior people. SMS codes are better than nothing, but they're the weakest form of MFA and the easiest to socially engineer. The accounts with access to client funds and firm banking should be on stronger methods, the Authenticator app with number matching at minimum, ideally phishing-resistant methods for anyone with elevated access.
No conditional logic at all. Firms on Business Premium or E3/E5 licensing are already paying for Conditional Access, the ability to require MFA everywhere, block sign-ins from countries you don't operate in, and demand a managed device for sensitive data. Most haven't configured any of it. The license cost is being paid; the protection isn't being collected.
What to actually do
If you're a practice manager or operations director, you don't need to configure any of this yourself. You need to ask the right questions and expect specific answers:
"Is MFA enforced for every single user, with zero exclusions?" The answer should be yes, backed by a report from the tenant — not a verbal assurance.
"Is legacy authentication blocked?" Again: yes, evidenced. If the answer involves "we think so", it needs checking against the sign-in logs.
"What MFA method are our partners and accounts team using?" If the answer is text messages, ask for a plan to move them to something stronger.
"Are we using the Conditional Access features we're already licensed for?" If your firm is on Business Premium or above and the answer is no, you're leaving paid-for protection switched off.
None of this requires new spend for most firms. It requires someone to look, and someone to own the answer.
Where to start
The honest starting point is knowing what your tenant actually looks like today — not what it was set up as three years ago, and not what everyone assumes. The sign-in logs and configuration will tell you in an afternoon.
If you'd like a second pair of eyes on it, we offer a free M365 Security Review, on-site or remote. We'll show you exactly where the gaps are, in plain English, whether or not you ever work with us afterwards. Get in touch and we'll set it up.
The Ultimate Guide to SCCM Primary Site Migration: Windows Server 2016 to Server 2022
Ready to transform your business?
Let's discuss how our Microsoft solutions can drive your business forward. Get a free consultation and discover what's possible.
