The Microsoft 365 Security Features Every CPA Firm Should Already Be Using
If your accounting practice runs on Microsoft 365 — and most practices in southern Nevada do — you’re already paying for the security controls that map to IRS Publication 4557 and the Written Information Security Plan every paid preparer is expected to maintain. They’re sitting there, turned off, doing nothing.
Microsoft 365 Business Premium includes a surprisingly capable security stack. The problem is that most businesses (and many IT providers) never configure it past the basics.
What you’re probably not using
Conditional Access
What it does: Controls how and where people can sign in. You can require MFA from outside the office, block sign-ins from countries you don’t operate in, and force compliant devices.
Why it matters: A stolen password from an IP address in another country gets blocked automatically. No human intervention needed.
Default state: Off. Requires Microsoft Entra ID P1, which is included in Business Premium but needs to be configured.
Microsoft Defender for Business
What it does: Endpoint detection and response (EDR) for every device. Monitors behavior, flags anomalies, can isolate compromised machines remotely.
Why it matters: This is the same category of tool that costs $5-10/endpoint/month from third-party vendors, and it’s included in your M365 license.
Default state: Available but not deployed. Requires agent installation on each device and policy configuration.
Data Loss Prevention (DLP)
What it does: Scans emails and files for sensitive information — credit card numbers, SSNs, health records — and prevents them from being shared inappropriately.
Why it matters: Compliance requirements for HIPAA, PCI, and other regulations often require DLP controls. You may already have the tool to satisfy the requirement.
Default state: Off. Requires policy creation defining what sensitive data looks like in your context.
Email Authentication (SPF, DKIM, DMARC)
What it does: Prevents attackers from sending emails that appear to come from your domain. SPF defines which servers can send on your behalf. DKIM cryptographically signs your emails. DMARC tells receiving servers what to do with emails that fail the checks.
Why it matters: Without these, anyone can send an email that looks like it’s from you. This is how business email compromise attacks work — an attacker sends an invoice from what appears to be your email address.
Default state: SPF is partially configured by default. DKIM and DMARC usually are not.
Safe Attachments and Safe Links
What it does: Opens email attachments in a sandbox before delivering them. Rewrites URLs to check them at click time against known threats.
Why it matters: Zero-day malware in attachments gets caught before it reaches the inbox. Malicious links that were clean at delivery time but weaponized later still get blocked.
Default state: Available in Business Premium via Defender for Office 365 Plan 1. Requires activation and policy configuration.
Why these features stay off
Three reasons:
- The business doesn’t know they exist. M365 licensing is confusing. Most businesses don’t know what they’re paying for.
- The IT provider hasn’t configured them. Not all providers are M365 specialists. Some set up email and file sharing and stop there.
- Fear of breaking things. Conditional access and DLP can block legitimate work if configured too aggressively. It takes experience to set the right policies.
What to do about it
Start by checking which M365 plan you’re on. Business Premium ($22/user/month U.S. list, annual commitment) includes everything listed above. Business Standard ($14/user/month U.S. list, annual commitment) does not include Defender for Business or full Conditional Access. Those are Microsoft list prices and are subject to change.
If you’re already on Premium and these features aren’t configured, you’re leaving significant security value on the table. A managed IT provider who specializes in M365 can audit your current configuration and enable what’s missing — usually in a few days, not weeks.
If you’re on Standard and need these capabilities, the upgrade is $8/user/month at current list. For 15 seats, that’s $120/month for a security stack that would cost significantly more from standalone vendors.
Either way, the first step is knowing what you have. Get an assessment and we’ll show you exactly what’s configured and what’s not.