How an Accounting Firm in Vienna Locked Down Its Microsoft 365 Environment

Tax season had just started when a due diligence questionnaire landed in the inbox of a 35-person accounting firm in Vienna, Virginia. A fast-growing engineering company evaluating the firm as its new accounting partner wanted to know who currently had access to its financial information and how that access was reviewed. Client files were being pulled all day by full-time staff, a few contractors brought on for the busy period, and two seasonal preparers hired to cover the extra volume. The firm’s systems were working the way they always did, and the questionnaire arrived like any other piece of new-client paperwork. 

A simple ask, an incomplete answer 

The managing partner expected the response to take an afternoon. Instead, pulling together an accurate picture of who had access to what took most of a week. Permissions inside the firm’s Microsoft 365 environment had built up over several years. People joined, moved between service lines, covered a season on a temporary basis, and left, and each change added an access right, while the old ones were never taken away. That kind of drift happens easily inside any growing professional services firm. The American Bar Association’s 2023 Cybersecurity TechReport found that 41% of law firms with 10 to 49 attorneys, a signal for professional services firms of a similar size, had already been asked by a client to hand over their security requirements documentation. Responsibility for reviewing who had access to what had never landed with one person. 

What the review turned up 

Once the firm looked properly, a few specifics stood out. A former employee who had left eighteen months earlier still had an active account with access to client tax files. A study by Beyond Identity found that more than eight in ten former employees said they still had access to at least one account from a previous employer, often well after leaving. A handful of current staff, including two of the seasonal preparers, were signing into one shared Microsoft 365 admin account instead of their own, so nothing done inside the tenant could be tied to a specific person. The firm also had barely any sign-in or audit logging switched on, so there would have been little to check against if something had gone wrong. 

The specifics stood on their own. Leadership couldn’t say with confidence who had access to client financial data or what any of them had done with it. For a firm the Federal Trade Commission classifies as a financial institution under the Gramm-Leach-Bliley Act, with a legal duty to control who can reach customer information, that shortfall carried weight well beyond one email from one prospective client. 

Fixing it without stopping the clock 

The timing made all of this harder than it needed to be. Rebuilding access controls in the middle of the firm’s busiest quarter risked locking someone out of a file they needed that afternoon, and client work needed to continue while the problem got fixed. So the review ran while the season carried on around it. The departed employee’s account came off first, since removing it carried no risk to anyone still working. The shared admin login took longer because replacing it with individual named accounts meant untangling who needed admin rights in the first place. Once that was done, every action inside Microsoft 365 could finally be tied to a person. From there, current staff access was checked against what each person’s role required, and the access rights that years of change had left behind were stripped back. Conditional access policies were turned on to control when and how sensitive systems could be reached, and sign-in and activity logging were switched on so there would be a record going forward. Ownership of reviewing access twice a year went to one person on the leadership team, so the task stopped depending on whoever happened to notice a problem next. 

The firm stayed honest about the limits of the old records, saying so wherever a clean history was missing, then building the process that would stop the same weakness from reappearing unnoticed. Access reviews of this kind sit inside the wider cybersecurity for firms whose data is regulated, where documentation and monitoring matter as much as the tools themselves. 

What changes when there’s a record 

A few months later, a second due diligence request arrived from a different prospective client. Leadership could name who owned access management and when it had last been reviewed. The specific accounts that changed, and why, were written down, and the activity logs were there to check. The account that had sat open for eighteen months was long gone. The shared login no longer existed, and the whole exchange took a fraction of the time the first one had. 

That difference traced back to specific changes the firm made. Access management had a named owner and a review schedule that ran on a fixed cycle. Changes were written down as they happened, and activity inside the tenant could be traced back to the person who caused it. That kind of record builds up gradually, through months of routine review that happen long before anyone comes asking to see them. 

If a client, insurer, or auditor asked your firm the same thing today, would you have an answer ready? BASE Solutions’ Governance and Audit-Readiness Checklist covers the specific evidence to have on hand across five areas of the business. 

If this made you pause on whether your own firm could give a clean answer to the same question, talk it through with BASE Solutions.

A firm that can produce all five when asked is demonstrating exactly the operational discipline insurers now price coverage around. 

If this makes you wonder whether your own firm would pass the same review, that’s worth a conversation before your next renewal.

Get a Free Consultation

Contact our experts today

Recent Posts:

Managed IT Services Can Cut IT Costs by 40% and Boost Efficiency by 50-60%.

Discover how the right IT partner can transform your business!