Microsoft 365 Copilot and the New Data Security Questions It Raises
Updated: Sep 2
Most accountancy firms now run on Microsoft 365 or a similar cloud platform, which shifts a lot of the security conversation to configuration rather than infrastructure. The tools to lock things down properly are usually already included in the licence — they just need to be turned on and set up correctly.
Getting the basics right
Conditional access policies, multi-factor authentication, and sensible defaults for SharePoint and OneDrive sharing catch a large share of common attack paths before they get anywhere. Left at default settings, most cloud platforms are more permissive than most firms would actually want.
Keeping visibility as tools multiply
As firms adopt more cloud apps — practice management, e-signature, AI assistants like Copilot — shadow IT becomes a real risk: tools staff sign up for individually, outside any central oversight. Regular reviews of what's actually connected to the firm's data help keep that visible rather than accumulating unnoticed.
If you'd like a review of your Microsoft 365 or Azure security configuration, we work with accountancy firms on exactly this.

Comments