1 min read
IRS Publication 4557 – Safeguarding Taxpayer Data
CPA firms are lucrative targets for hackers. They store, send, and receive Personally Identifiable Information (PII) for a living. Because CPA firms...
Accounting firms hold a strange position in the threat landscape. They don't process credit cards like a retailer or store medical charts like a hospital, but they hold something arguably more valuable to a criminal: complete financial identities. Social Security numbers, bank account details, W-2s, K-1s, payroll files, and years of tax returns all sit in one place, often accessible from laptops, phones, and tablets that leave the office every day.
Accounting firms hold a strange position in the threat landscape. They don't process credit cards like a retailer or store medical charts like a hospital, but they hold something arguably more valuable to a criminal: complete financial identities. Social Security numbers, bank account details, W-2s, K-1s, payroll files, and years of tax returns all sit in one place, often accessible from laptops, phones, and tablets that leave the office every day.
Microsoft 365 security has become the backbone of how firms protect that data, and Microsoft Intune is the piece of that backbone that most firms still leave out.
A firm can lock down SharePoint, require complex passwords, and train staff on phishing, and still lose client data the moment a laptop is stolen from a car or an employee logs into Outlook from a personal, unpatched phone. The IRS makes this point directly to tax professionals: every preparer, from a solo practitioner to a large firm, is a target for cybercriminals seeking to steal client data and file fraudulent returns in their clients' names. The IRS advises reviewing Publication 4557, Safeguarding Taxpayer Data, which lays out the security practices tax professionals are expected to follow.
That guidance doesn't stop at software settings. It extends to every device that touches taxpayer data. If a firm can't say with certainty which devices have access to client files, whether those devices are encrypted, or whether they can be wiped remotely after a loss, the firm has a gap that a written policy alone won't close. This is exactly the gap Intune is built to fill.
Microsoft Intune is Microsoft's cloud-based endpoint management platform, built to enforce security policy across the Windows, macOS, iOS, and Android devices that connect to a firm's data. According to Microsoft's own documentation, Intune controls devices through policy, covering everything from disk encryption and minimum OS versions to blocking simple passwords and preventing unauthorized access to organizational resources.
For a partner's firm-owned laptop, Intune fully enrolls the device and applies a security baseline: BitLocker encryption, Microsoft Defender configuration, firewall rules, and automatic compliance checks that flag the device the moment it drifts out of policy. For the associate who checks client email from a personal phone, Intune can apply app protection policies instead of full enrollment, restricting how Outlook, Teams, or SharePoint data can be copied, saved, or shared outside the managed app, without taking control of the employee's personal device. Firms rarely have one uniform device population. Most run a mix of firm-issued hardware and personal devices used for convenience during busy season, and Intune is built to handle both categories differently rather than forcing every device into the same box.
The IRS guidance for tax professionals doesn't exist in isolation. Publication 4557 sits on top of a legal obligation that tax preparers, as businesses handling consumer financial data, fall under the Federal Trade Commission's Safeguards Rule, part of the Gramm-Leach-Bliley Act. The FTC's own guidance describes what covered firms must maintain: a written security program, access controls, encryption of customer data, and multi-factor authentication for anyone accessing systems containing customer information.
Two of those requirements map almost exactly onto what Intune enforces at the device level. Access control focuses on whether the device attempting to log in meets the firm's security standards before it's allowed anywhere near client data. Intune's compliance policies do this by checking device health at the point of access and working with Microsoft Entra ID to block sign-ins from devices that don't meet the bar, an approach Microsoft frames as central to a Zero Trust strategy for endpoint security. Encryption is the second overlap. A firm can require BitLocker on every Windows laptop and enforce it centrally through Intune's device configuration profiles, rather than relying on each employee to enable it correctly on their own.
This matters because these aren't abstract best practices. The FTC's rule became fully enforceable for most provisions on June 9, 2023, and it applies regardless of firm size, meaning a two-partner tax practice carries the same MFA and access control obligations as a much larger firm.
Every firm preparing returns is expected to maintain a Written Information Security Plan, and the IRS points preparers toward Publication 4557 to build one that covers risk assessment, access controls, and incident response. A WISP that lists "devices must be secured" as a bullet point isn't the same as a WISP backed by a system that actually enforces that statement. When an examiner, cyber insurer, or client asks how the firm verifies that a stolen laptop can't be used to access tax files, "we have a policy" is a weaker answer than "the device is encrypted, monitored for compliance, and can be wiped remotely the moment we report it missing."
Intune gives a firm that second answer. Lost or stolen devices can be marked for remote wipe, removing organizational data without needing physical possession of the hardware. Employees who leave the firm can have their access revoked at the device level, not just at the account level. None of this replaces the human side of a WISP, staff training, incident response planning, or vendor vetting, but it gives the technical controls section of that plan something concrete and auditable to back it up.
Tax and accounting work doesn't happen only inside the office anymore. Staff pull up client files from home during filing season, partners review returns on a phone between meetings, and seasonal contractors sometimes work from personal machines the firm doesn't own outright. This is precisely the scenario Microsoft designed Intune's dual approach to address: full device management for firm-owned hardware, and application-level protection for personal devices where full enrollment isn't practical or welcome. A firm can require that any BYOD phone accessing Outlook do so through a managed app with copy-paste restrictions and remote data wipe capability, without ever touching the employee's photos or personal apps.
This flexibility is often what makes Intune practical for a firm that has resisted device management in the past, assuming it means confiscating control over how staff use their own phones. It doesn't have to. A firm can start with app protection policies for BYOD and full enrollment for firm-issued laptops, then adjust as the practice grows or as client contracts begin to ask pointed questions about data handling.
Firms already invest heavily in Microsoft 365 security through email filtering, conditional access, and data loss prevention. Those controls protect data while it lives inside Microsoft's cloud. Intune closes the gap at the edge, on the physical devices where that data actually gets opened, edited, and sometimes forgotten in a car console or airport lounge. For a profession built on protecting other people's most sensitive financial information, and regulated accordingly by both the IRS and the FTC, that edge is not the place to leave unmanaged.
A firm evaluating its security posture this year has a reasonable starting point: pull a list of every device with access to client tax files, and ask honestly whether the firm could remotely wipe each one today if it had to. If the answer is no for even one device, that's the gap Intune was built to close.
Ready to explore Intune for your CPA firm? At PK Tech, we have over 16 years of experience supporting businesses like yours navigate Microsoft 365 and beyond. We maintain AICPA's SOC 2 Type II attestation, verified through an independent third-party audit of our security and privacy controls. If you want help navigating or deploying Microsoft Intune, we can help. Schedule a call with our team.
1 min read
CPA firms are lucrative targets for hackers. They store, send, and receive Personally Identifiable Information (PII) for a living. Because CPA firms...
1 min read
With tax season in full swing, it seems fitting to review the importance of IRS Publication 4557. For those not in the work of tax, it may be...
1 min read
We're an MSP for accounting firms, and we see it all. Over the past several years, offshore labor has become increasingly common in the CPA space....