Strengthening Microsoft 365 Security and Compliance for FCA-Regulated Companies
For an FCA-regulated business, Microsoft 365 is rarely just an email platform.
It may contain:
customer communications
commercially sensitive documents
financial records
compliance evidence
Teams conversations
SharePoint sites
employee information
authentication and security data
That makes Microsoft 365 part of the organisation’s wider operational and regulatory risk.
The important point is:
Microsoft 365 can support FCA compliance, but buying Microsoft licences does not make a firm compliant.
The controls need to be:
selected → configured → monitored → tested → evidenced → regularly reviewed.
FCA Regulation Does Not Prescribe a Microsoft 365 Configuration
The FCA does not publish a checklist saying:
Enable Conditional Access Policy A.
Turn on Defender setting B.
Instead, regulated firms are expected to establish systems, controls and governance appropriate to their:
business
risks
customers
services
regulatory obligations
Microsoft 365 provides many of the technical capabilities that can support that framework.
The firm still has to determine what is appropriate.
That distinction is essential.
A business can own expensive Microsoft 365 security licences and still have:
weak administrator security
excessive SharePoint permissions
inconsistent MFA
poor logging
no tested recovery process
Licensing is capability.
Configuration and governance create protection.
1. Start With Identity
Identity is one of the most important Microsoft 365 security boundaries.
A compromised Microsoft account can potentially expose:
Exchange Online
Teams
OneDrive
SharePoint
connected applications
For most regulated businesses, MFA should therefore be treated as a baseline requirement.
But MFA alone is not necessarily enough.
Higher-risk accounts should receive stronger controls.
That includes:
administrators
finance staff
executives
compliance personnel
users with access to particularly sensitive data
Where practical, consider phishing-resistant authentication methods for privileged or higher-risk accounts rather than relying solely on passwords plus easily phished verification methods.
2. Use Conditional Access to Control How Accounts Are Used
Microsoft Entra Conditional Access allows access decisions to consider signals such as:
user
application
device
location
sign-in risk
That allows a regulated firm to move beyond:
correct password = access granted.
For example:
managed + compliant laptop + expected sign-in
may be permitted.
Whereas:
unknown device + unusual sign-in + sensitive application
could require stronger authentication or be blocked.
Policies should be introduced carefully.
Poorly designed Conditional Access can:
lock legitimate employees out
create dangerous exemptions
interfere with emergency access
Use controlled rollout and test groups before enforcing organisation-wide.
3. Reduce Permanent Administrative Privilege
One of the most damaging accounts an attacker can compromise is an administrator.
Review:
Global Administrators
Exchange Administrators
SharePoint Administrators
security roles
application administrators
Ask:
Does this person genuinely need this privilege all the time?
Use:
separate administrator identities
least privilege
strong MFA
temporary/eligible privileges where appropriate
regular access reviews
An engineer who needs to administer Exchange does not automatically need permanent Global Administrator access.
The same principle applies to:
service accounts
enterprise applications
third-party integrations
Dormant privileged access should be removed.
4. Strengthen Email Security
Email remains one of the most common routes into an organisation.
Threats include:
phishing
credential theft
impersonation
invoice fraud
malicious attachments
malicious links
Depending on licensing and requirements, Microsoft Defender for Office 365 can provide controls such as:
anti-phishing
Safe Links
Safe Attachments
impersonation protection
For FCA-regulated organisations, I would pay particular attention to users involved in:
payments
customer funds
financial approvals
regulatory reporting
senior management
Technical controls should also be supported by security-awareness training.
The most sophisticated filtering system cannot stop every employee from willingly entering credentials into a convincing phishing page.
5. Secure the Device, Not Just the Account
A strong Microsoft identity can still be undermined by an infected or unmanaged endpoint.
Microsoft Intune can help enforce standards such as:
encryption
supported OS versions
current patches
endpoint security
firewall
screen lock
approved applications
restricted local administrator rights
Conditional Access can then use compliance status when deciding whether a device is allowed to access Microsoft 365.
This creates a much stronger model:
trusted identity + trusted device
rather than:
correct password from anything connected to the internet.
6. Review SharePoint, Teams and OneDrive Permissions
One of the biggest Microsoft 365 risks is often not malware.
It is oversharing.
Over time, organisations accumulate:
old Teams
forgotten SharePoint sites
guest users
anonymous sharing links
inherited permissions
former contractors
That can create situations where far more people can access sensitive information than intended.
Regularly review:
external users
guest accounts
site membership
anonymous links
shared folders
privileged groups
Pay particular attention to repositories containing:
customer data
financial information
complaints
compliance files
board materials
Copilot and search also make good permissions hygiene increasingly important because users can more easily discover content they already have permission to access.
7. Classify Information Before Trying to Protect It
It is difficult to build effective data controls if the organisation cannot answer:
What information is sensitive?
Microsoft Purview sensitivity labels can support an information-classification model.
A regulated business might adopt categories such as:
Public
Internal
Confidential
Customer Confidential
Regulatory
Highly Restricted
Depending on configuration and licensing, labels can help:
encrypt information
restrict access
apply visual markings
control sharing
But avoid creating 25 labels employees cannot understand.
A smaller, well-defined classification model is usually more effective.
8. Use DLP Around Real Business Risks
Microsoft Purview Data Loss Prevention can identify and respond when sensitive information is being shared inappropriately.
Examples might include:
customer financial details
payment information
identity documents
sensitive personal data
protected internal documents
Possible responses include:
warning the employee
requesting justification
blocking the action
generating an alert
Do not start by enabling every possible DLP rule.
Start with the organisation’s highest-value information and the realistic routes through which it could leave the business.
9. Verify Audit Logging — Do Not Assume It Is Enabled
This is one of the most important changes I would make to the live article.
Microsoft says auditing is generally enabled by default for Microsoft 365 organisations, but not for SMB licences including Microsoft 365 Business Basic, Business Standard and Business Premium.
That means an SME using Business Premium should explicitly verify:
Is Microsoft Purview Audit actually recording activity?
This matters because audit records can help reconstruct:
administrator changes
file activity
mailbox changes
user activity
security incidents
For a regulated firm, discovering after an incident that auditing was never switched on is a preventable failure.
10. Make Sure Audit Retention Is Long Enough
Audit logging and audit retention are separate questions.
Microsoft currently retains Audit Standard records for 180 days, while eligible Audit Premium configurations can provide longer retention. Microsoft documents one-year default retention for certain E5/Purview-licensed workloads and custom policies extending audit retention to as much as 10 years, subject to the appropriate licensing.
That does not mean every FCA firm needs ten years of Microsoft audit logs.
It means the firm needs to decide:
How long must we retain evidence for our risks and obligations?
Then confirm Microsoft licensing and policy actually meet that requirement.
11. Retention Policies Should Come From Compliance Requirements
Do not let the IT department independently decide:
“Seven years sounds sensible.”
Retention should be agreed with:
compliance
legal
data protection
records management
Then Microsoft Purview should implement those approved requirements.
Different information may require different treatment.
For example:
customer records
employee information
regulatory evidence
financial records
legal holds
investigation material
Keeping everything forever is not automatically safer or more compliant.
Neither is deleting it too soon.
12. Treat Operational Resilience as More Than Microsoft Availability
The FCA defines operational resilience as the ability to prevent, adapt and respond to, recover and learn from operational disruption. Firms within scope were required by 31 March 2025 to demonstrate that important business services could remain within their impact tolerances.
The FCA’s March 2026 observations emphasised that this is ongoing work, including continued:
mapping
scenario testing
self-assessment
improvement.
For Microsoft 365, ask:
What happens if Exchange Online is unavailable?
What happens if administrators are locked out?
What happens if Entra authentication is disrupted?
What happens if SharePoint is unavailable during a critical process?
Resilience planning may include:
alternative communications
emergency administrator access
documented offline procedures
independent backups
supplier contacts
manual workarounds
The fact that Microsoft operates highly resilient infrastructure does not remove the firm's own operational-resilience responsibilities.
13. Microsoft Is Now Part of the UK's Critical Third-Party Regime
This is worth adding in a 2026 article.
In July 2026, UK regulators announced the first designated Critical Third Parties, including Microsoft Ireland Operations Ltd, alongside AWS, Google Cloud and Oracle. Regulatory oversight of those designated providers began on 13 July 2026.
That is significant.
But firms should not misinterpret it.
The FCA explicitly states that the CTP regime does not remove the accountability of firms, their boards or senior management for remaining resilient and complying with existing outsourcing requirements.
In other words:
Microsoft being regulated as a critical third party does not outsource your firm's accountability to Microsoft.
14. Prepare Now for the March 2027 Incident-Reporting Rules
The FCA finalised new operational-incident and material third-party reporting requirements on 18 March 2026.
They come into force on:
18 March 2027.
The FCA says the new framework will introduce a more standardised process for reporting material operational incidents and third-party arrangements.
Firms should use the preparation period now.
For Microsoft 365, make sure the incident-response process answers:
Who declares an incident?
Who investigates Microsoft 365 activity?
Who contacts the FCA?
Who contacts the ICO where required?
Who preserves evidence?
Who contacts Microsoft and the MSP?
What happens if normal email is unavailable?
Do not wait until March 2027 to design the process.
15. Third-Party Governance Includes Your MSP
Microsoft is not the only supplier involved.
An outsourced IT provider may have access to:
Microsoft 365 administration
endpoints
backups
security tools
networks
That makes the MSP part of the regulated firm’s wider supplier-risk picture.
Understand:
what access the provider has
how administrators authenticate
how privileged actions are logged
how incidents are escalated
what subcontractors are used
how service termination works
how credentials and data are returned
Outsourcing technical work does not outsource regulatory accountability.
16. Back Up Microsoft 365 According to Your Recovery Requirements
Microsoft provides extensive service resilience and native recovery functionality.
But firms should still determine whether that meets their own requirements around:
accidental deletion
malicious deletion
retention
ransomware
independent recovery
regulatory evidence
Backup design should be based on:
What do we need to recover?
How far back?
How quickly?
Then test restoration.
A backup that has never been restored is still partly an assumption.
17. Test Security Incidents, Not Just Backups
Scenario testing should include events such as:
Administrator account compromised
Can you remove the attacker and restore trusted access?
Business email compromise
Can you identify mailbox rules, forwarding and fraudulent activity?
Microsoft 365 unavailable
Can critical staff still communicate?
Ransomware attack
Can you recover business information and identities into a trusted environment?
The FCA’s current operational-resilience work explicitly stresses testing against severe but plausible scenarios and remaining within impact tolerances.
Exercises should reveal weaknesses.
That is their purpose.
18. Use Microsoft Secure Score — but Do Not Treat It as FCA Compliance
Microsoft Secure Score is useful for identifying recommended improvements.
It can help expose:
missing controls
configuration weaknesses
identity issues
But it is not:
an FCA audit
proof of compliance
a penetration test
a complete cyber-risk assessment
The correct question is not:
“How do we get to 100%?”
It is:
“Which actions materially reduce our regulatory and operational risk?”
A slightly lower score with understood risk decisions can be better than blindly implementing recommendations purely to make the number larger.
A Practical FCA Microsoft 365 Review
I would review a regulated Microsoft 365 environment across these areas:
1. Identity — MFA, Conditional Access and privileged accounts.
2. Endpoints — Intune, encryption and endpoint security.
3. Email — phishing, impersonation and malicious-content protection.
4. Data — permissions, sensitivity labels and DLP.
5. Audit — confirm it is actually enabled and retained appropriately.
6. Records — retention and eDiscovery requirements.
7. Recovery — backups and restore testing.
8. Resilience — important business services and impact tolerances.
9. Incidents — response, evidence and regulatory reporting.
10. Third parties — Microsoft, MSPs and other material providers.
11. Monitoring — alerts and suspicious activity.
12. Governance — documented ownership, review and senior-management oversight.
That gives you something much more useful than asking:
“Is our Microsoft 365 secure?”
How Hamilton Group Can Help
Hamilton Group can help FCA-regulated businesses turn Microsoft 365 security controls into a managed, documented and reviewable environment.
We can assist with:
Microsoft 365 security reviews
Microsoft Entra ID
Conditional Access
MFA
privileged-access reviews
Microsoft Defender
Intune
SharePoint and Teams permissions
Microsoft Purview
sensitivity labels
DLP
audit and retention
backup and recovery
incident-response preparation
operational-resilience planning
security awareness training
The objective is not simply to switch on as many Microsoft features as possible.
It is to make sure the controls match the firm’s actual risks, regulatory requirements and important business services—and that there is evidence they are working.
Visit hgmssp.com or call 0330 043 0069 to discuss a Microsoft 365 security and compliance review.
This article provides general information and is not legal or regulatory advice. Firms should obtain specialist advice appropriate to their permissions, activities and regulatory obligations.