Most accounting firms already pay for Microsoft 365. Far fewer have turned on the parts of it built to stop the exact threats they face every tax season: business email compromise, credential theft, and accidental exposure of client Social Security numbers and bank details. The license is active. The default settings, in most tenants, are not doing the job.
That gap matters more for accounting firms than for almost any other small business category, because the law treats them differently. The Federal Trade Commission's Safeguards Rule requires firms that handle client financial data to maintain a written information security program with administrative and technical safeguards. The IRS backs this up directly: its guidance for tax preparers points firms to Publication 4557, Safeguarding Taxpayer Data, as the starting point for building that plan, and the requirement applies to sole practitioners and large firms alike. Compliance isn't the only reason to turn on these tools, but it removes any excuse for leaving them off.
Turning on MFA in Microsoft Entra ID doesn't automatically block a compromised password. If legacy authentication protocols such as IMAP or POP are still permitted, an attacker can often authenticate without ever touching the MFA prompt. Firms get real protection only when they pair MFA with a Conditional Access policy that blocks legacy authentication outright and requires modern, verified sign-in for every user, every time.
Microsoft describes it as a policy engine that pulls together signals like user identity, device, location, and real-time risk to decide whether to allow, block, or challenge a sign-in attempt, rather than treating every login the same way regardless of context. Microsoft's own documentation notes that the engine evaluates over 40 TB of identity-related signals to make that call. For a firm handling client refunds and payroll data, this is the difference between a stolen password being a dead end and it being an open door.
A practical starting point: require MFA for all admin accounts, block legacy authentication tenant-wide, and require a compliant or registered device for anyone accessing SharePoint or Exchange from outside the office network. Microsoft's guidance on planning a Conditional Access deployment walks through staging these policies safely, including testing them in report-only mode before enforcing them against the whole staff.
A tax preparer forwarding a client's W-2 to a personal Gmail account "just to finish it at home" is not malicious. It's still a data security failure, and it's the kind of thing regulators expect firms to have controls against. Microsoft Purview's Data Loss Prevention tools exist for exactly this scenario. Purview DLP can identify sensitive information types, such as Social Security numbers or bank routing numbers, across Exchange, SharePoint, OneDrive, and Teams, and then take action automatically. That can mean warning the employee with a policy tip before they hit send, blocking the transfer outright, or logging the attempt for review.
Pair this with sensitivity labels, which let a firm mark a document as "Client Confidential" and have that classification travel with the file wherever it goes, including outside the tenant. Microsoft's Purview documentation on sensitivity labels describes this as built-in classification and labeling that works natively across Microsoft 365 apps, so the protection isn't dependent on the employee remembering to apply it manually every time. Once a firm has mapped where client data actually lives, a DLP policy that catches accidental oversharing takes a few hours to configure and runs quietly in the background from then on.
Many firms still email tax documents as unprotected PDF attachments, sometimes password-protected with a code sent in a follow-up email, which defeats the purpose. Microsoft 365 includes message encryption that works from inside Outlook: a preparer can mark a message as encrypted with a sensitivity label or a simple toggle, and the recipient opens it through a standard, authenticated flow rather than a clunky third-party portal. Because it's built into the tenant, it doesn't require a new tool for staff to learn or a new login for clients to fumble with during a busy filing week.
The IRS and Security Summit partners have flagged tax professionals as a recurring target for phishing and business email compromise, and the pattern rarely changes: a fraudulent email convinces one employee to click a link or hand over credentials, and the attacker uses that inbox to intercept wire instructions or client refunds. Attack Simulation Training, part of Microsoft Defender for Office 365, lets a firm send realistic but harmless phishing emails to its own staff and then routes anyone who clicks straight into a short, targeted training module. Microsoft's documentation describes the tool as measuring and managing social engineering risk with real-world phishing payloads, and reporting shows which employees clicked, which entered credentials, and which correctly reported the message instead.
For a firm with high staff turnover during tax season, this matters more than a once-a-year training video. New hires and seasonal preparers get tested against the same threats a real attacker would use, and the firm gets a documented record of who needs follow-up training rather than a vague sense that "everyone did the annual course."
Even a firm with MFA enforced everywhere is still exposed if it never looks at how sign-ins actually behave over time. Microsoft Entra ID Protection scores each sign-in and each user account for risk, drawing on signals like impossible travel, sign-ins from unfamiliar locations, or credentials that have shown up in a known leak. Conditional Access can then act on that score automatically. It can force a password reset when a user's risk level is high, or block the sign-in outright, instead of waiting for an admin to spot something odd in a log days later. Microsoft's documentation notes this risk data can feed directly into Conditional Access policies once a firm has the P2 licensing tier that includes it, which turns a manual review process into something closer to a tripwire.
This matters because the biggest threat to an accounting firm's inbox usually isn't a brute-force attack. It's a set of stolen credentials, purchased cheaply after some unrelated breach, quietly tested against dozens of firms until one login works. Risk-based sign-in detection is one of the few controls built to catch that specific pattern before a preparer's mailbox becomes the launchpad for a wire fraud attempt against a client.
None of this requires an enterprise IT budget. Conditional Access, Purview DLP, sensitivity labels, message encryption, and Attack Simulation Training are available on plans many firms already hold or can add without switching platforms entirely. What they require instead is someone actually going into the admin center and turning them on, then checking back periodically as staff and threats change.
A firm that configures these five areas closes gaps attackers already know how to find, and builds the documentation trail that a Written Information Security Plan under the FTC Safeguards Rule expects: a record of what controls exist, who's responsible for them, and how the firm tests that they still work. Given how much of that groundwork is already sitting inside a Microsoft 365 subscription, the technology is the easy part. The harder part is making the time to configure it before the next filing season rather than after a breach.
Are you curious if your firm is tapping into everything Microsoft 365 offers? At PK Tech, we have over 16 years of experience supporting businesses like yours navigate Microsoft 365 and beyond. We maintain AICPA's SOC 2 Type II attestation, verified through an independent third-party audit of our security and privacy controls.
If you want help navigating or deploying Microsoft 365 security features, we can help. Schedule a call with our team.