Skip to main content

Strengthening Microsoft 365 Security and Compliance for FCA-Regulated Companies

Media Strengthening Office 365 Security and Compliance for FCA-Regulated Companies

 

For an FCA-regulated business, Microsoft 365 is rarely just an email platform.

It may contain:

customer communications

commercially sensitive documents

financial records

compliance evidence

Teams conversations

SharePoint sites

employee information

authentication and security data


That makes Microsoft 365 part of the organisation’s wider operational and regulatory risk.

The important point is:

Microsoft 365 can support FCA compliance, but buying Microsoft licences does not make a firm compliant.

The controls need to be:

selected → configured → monitored → tested → evidenced → regularly reviewed.

FCA Regulation Does Not Prescribe a Microsoft 365 Configuration

The FCA does not publish a checklist saying:

Enable Conditional Access Policy A.

Turn on Defender setting B.

Instead, regulated firms are expected to establish systems, controls and governance appropriate to their:

business

risks

customers

services

regulatory obligations


Microsoft 365 provides many of the technical capabilities that can support that framework.

The firm still has to determine what is appropriate.

That distinction is essential.

A business can own expensive Microsoft 365 security licences and still have:

weak administrator security

excessive SharePoint permissions

inconsistent MFA

poor logging

no tested recovery process


Licensing is capability.

Configuration and governance create protection.

1. Start With Identity

Identity is one of the most important Microsoft 365 security boundaries.

A compromised Microsoft account can potentially expose:

Exchange Online

Teams

OneDrive

SharePoint

connected applications


For most regulated businesses, MFA should therefore be treated as a baseline requirement.

But MFA alone is not necessarily enough.

Higher-risk accounts should receive stronger controls.

That includes:

administrators

finance staff

executives

compliance personnel

users with access to particularly sensitive data


Where practical, consider phishing-resistant authentication methods for privileged or higher-risk accounts rather than relying solely on passwords plus easily phished verification methods.

2. Use Conditional Access to Control How Accounts Are Used

Microsoft Entra Conditional Access allows access decisions to consider signals such as:

user

application

device

location

sign-in risk


That allows a regulated firm to move beyond:

correct password = access granted.

For example:

managed + compliant laptop + expected sign-in

may be permitted.

Whereas:

unknown device + unusual sign-in + sensitive application

could require stronger authentication or be blocked.

Policies should be introduced carefully.

Poorly designed Conditional Access can:

lock legitimate employees out

create dangerous exemptions

interfere with emergency access


Use controlled rollout and test groups before enforcing organisation-wide.

3. Reduce Permanent Administrative Privilege

One of the most damaging accounts an attacker can compromise is an administrator.

Review:

Global Administrators

Exchange Administrators

SharePoint Administrators

security roles

application administrators


Ask:

Does this person genuinely need this privilege all the time?

Use:

separate administrator identities

least privilege

strong MFA

temporary/eligible privileges where appropriate

regular access reviews


An engineer who needs to administer Exchange does not automatically need permanent Global Administrator access.

The same principle applies to:

service accounts

enterprise applications

third-party integrations


Dormant privileged access should be removed.

4. Strengthen Email Security

Email remains one of the most common routes into an organisation.

Threats include:

phishing

credential theft

impersonation

invoice fraud

malicious attachments

malicious links


Depending on licensing and requirements, Microsoft Defender for Office 365 can provide controls such as:

anti-phishing

Safe Links

Safe Attachments

impersonation protection


For FCA-regulated organisations, I would pay particular attention to users involved in:

payments

customer funds

financial approvals

regulatory reporting

senior management


Technical controls should also be supported by security-awareness training.

The most sophisticated filtering system cannot stop every employee from willingly entering credentials into a convincing phishing page.

5. Secure the Device, Not Just the Account

A strong Microsoft identity can still be undermined by an infected or unmanaged endpoint.

Microsoft Intune can help enforce standards such as:

encryption

supported OS versions

current patches

endpoint security

firewall

screen lock

approved applications

restricted local administrator rights


Conditional Access can then use compliance status when deciding whether a device is allowed to access Microsoft 365.

This creates a much stronger model:

trusted identity + trusted device

rather than:

correct password from anything connected to the internet.

6. Review SharePoint, Teams and OneDrive Permissions

One of the biggest Microsoft 365 risks is often not malware.

It is oversharing.

Over time, organisations accumulate:

old Teams

forgotten SharePoint sites

guest users

anonymous sharing links

inherited permissions

former contractors


That can create situations where far more people can access sensitive information than intended.

Regularly review:

external users

guest accounts

site membership

anonymous links

shared folders

privileged groups


Pay particular attention to repositories containing:

customer data

financial information

complaints

compliance files

board materials


Copilot and search also make good permissions hygiene increasingly important because users can more easily discover content they already have permission to access.

7. Classify Information Before Trying to Protect It

It is difficult to build effective data controls if the organisation cannot answer:

What information is sensitive?

Microsoft Purview sensitivity labels can support an information-classification model.

A regulated business might adopt categories such as:

Public

Internal

Confidential

Customer Confidential

Regulatory

Highly Restricted


Depending on configuration and licensing, labels can help:

encrypt information

restrict access

apply visual markings

control sharing


But avoid creating 25 labels employees cannot understand.

A smaller, well-defined classification model is usually more effective.

8. Use DLP Around Real Business Risks

Microsoft Purview Data Loss Prevention can identify and respond when sensitive information is being shared inappropriately.

Examples might include:

customer financial details

payment information

identity documents

sensitive personal data

protected internal documents


Possible responses include:

warning the employee

requesting justification

blocking the action

generating an alert


Do not start by enabling every possible DLP rule.

Start with the organisation’s highest-value information and the realistic routes through which it could leave the business.

9. Verify Audit Logging — Do Not Assume It Is Enabled

This is one of the most important changes I would make to the live article.

Microsoft says auditing is generally enabled by default for Microsoft 365 organisations, but not for SMB licences including Microsoft 365 Business Basic, Business Standard and Business Premium.

That means an SME using Business Premium should explicitly verify:

Is Microsoft Purview Audit actually recording activity?

This matters because audit records can help reconstruct:

administrator changes

file activity

mailbox changes

user activity

security incidents


For a regulated firm, discovering after an incident that auditing was never switched on is a preventable failure.

10. Make Sure Audit Retention Is Long Enough

Audit logging and audit retention are separate questions.

Microsoft currently retains Audit Standard records for 180 days, while eligible Audit Premium configurations can provide longer retention. Microsoft documents one-year default retention for certain E5/Purview-licensed workloads and custom policies extending audit retention to as much as 10 years, subject to the appropriate licensing.

That does not mean every FCA firm needs ten years of Microsoft audit logs.

It means the firm needs to decide:

How long must we retain evidence for our risks and obligations?

Then confirm Microsoft licensing and policy actually meet that requirement.

11. Retention Policies Should Come From Compliance Requirements

Do not let the IT department independently decide:

“Seven years sounds sensible.”

Retention should be agreed with:

compliance

legal

data protection

records management


Then Microsoft Purview should implement those approved requirements.

Different information may require different treatment.

For example:

customer records

employee information

regulatory evidence

financial records

legal holds

investigation material


Keeping everything forever is not automatically safer or more compliant.

Neither is deleting it too soon.

12. Treat Operational Resilience as More Than Microsoft Availability

The FCA defines operational resilience as the ability to prevent, adapt and respond to, recover and learn from operational disruption. Firms within scope were required by 31 March 2025 to demonstrate that important business services could remain within their impact tolerances.

The FCA’s March 2026 observations emphasised that this is ongoing work, including continued:

mapping

scenario testing

self-assessment

improvement.


For Microsoft 365, ask:

What happens if Exchange Online is unavailable?

What happens if administrators are locked out?

What happens if Entra authentication is disrupted?

What happens if SharePoint is unavailable during a critical process?

Resilience planning may include:

alternative communications

emergency administrator access

documented offline procedures

independent backups

supplier contacts

manual workarounds


The fact that Microsoft operates highly resilient infrastructure does not remove the firm's own operational-resilience responsibilities.

13. Microsoft Is Now Part of the UK's Critical Third-Party Regime

This is worth adding in a 2026 article.

In July 2026, UK regulators announced the first designated Critical Third Parties, including Microsoft Ireland Operations Ltd, alongside AWS, Google Cloud and Oracle. Regulatory oversight of those designated providers began on 13 July 2026.

That is significant.

But firms should not misinterpret it.

The FCA explicitly states that the CTP regime does not remove the accountability of firms, their boards or senior management for remaining resilient and complying with existing outsourcing requirements.

In other words:

Microsoft being regulated as a critical third party does not outsource your firm's accountability to Microsoft.

14. Prepare Now for the March 2027 Incident-Reporting Rules

The FCA finalised new operational-incident and material third-party reporting requirements on 18 March 2026.

They come into force on:

18 March 2027.

The FCA says the new framework will introduce a more standardised process for reporting material operational incidents and third-party arrangements.

Firms should use the preparation period now.

For Microsoft 365, make sure the incident-response process answers:

Who declares an incident?

Who investigates Microsoft 365 activity?

Who contacts the FCA?

Who contacts the ICO where required?

Who preserves evidence?

Who contacts Microsoft and the MSP?

What happens if normal email is unavailable?


Do not wait until March 2027 to design the process.

15. Third-Party Governance Includes Your MSP

Microsoft is not the only supplier involved.

An outsourced IT provider may have access to:

Microsoft 365 administration

endpoints

backups

security tools

networks


That makes the MSP part of the regulated firm’s wider supplier-risk picture.

Understand:

what access the provider has

how administrators authenticate

how privileged actions are logged

how incidents are escalated

what subcontractors are used

how service termination works

how credentials and data are returned


Outsourcing technical work does not outsource regulatory accountability.

16. Back Up Microsoft 365 According to Your Recovery Requirements

Microsoft provides extensive service resilience and native recovery functionality.

But firms should still determine whether that meets their own requirements around:

accidental deletion

malicious deletion

retention

ransomware

independent recovery

regulatory evidence


Backup design should be based on:

What do we need to recover?

How far back?

How quickly?

Then test restoration.

A backup that has never been restored is still partly an assumption.

17. Test Security Incidents, Not Just Backups

Scenario testing should include events such as:

Administrator account compromised

Can you remove the attacker and restore trusted access?

Business email compromise

Can you identify mailbox rules, forwarding and fraudulent activity?

Microsoft 365 unavailable

Can critical staff still communicate?

Ransomware attack

Can you recover business information and identities into a trusted environment?

The FCA’s current operational-resilience work explicitly stresses testing against severe but plausible scenarios and remaining within impact tolerances.

Exercises should reveal weaknesses.

That is their purpose.

18. Use Microsoft Secure Score — but Do Not Treat It as FCA Compliance

Microsoft Secure Score is useful for identifying recommended improvements.

It can help expose:

missing controls

configuration weaknesses

identity issues


But it is not:

an FCA audit

proof of compliance

a penetration test

a complete cyber-risk assessment


The correct question is not:

“How do we get to 100%?”

It is:

“Which actions materially reduce our regulatory and operational risk?”

A slightly lower score with understood risk decisions can be better than blindly implementing recommendations purely to make the number larger.

A Practical FCA Microsoft 365 Review

I would review a regulated Microsoft 365 environment across these areas:

1. Identity — MFA, Conditional Access and privileged accounts.


2. Endpoints — Intune, encryption and endpoint security.


3. Email — phishing, impersonation and malicious-content protection.


4. Data — permissions, sensitivity labels and DLP.


5. Audit — confirm it is actually enabled and retained appropriately.


6. Records — retention and eDiscovery requirements.


7. Recovery — backups and restore testing.


8. Resilience — important business services and impact tolerances.


9. Incidents — response, evidence and regulatory reporting.


10. Third parties — Microsoft, MSPs and other material providers.


11. Monitoring — alerts and suspicious activity.


12. Governance — documented ownership, review and senior-management oversight.

 

That gives you something much more useful than asking:

“Is our Microsoft 365 secure?”

How Hamilton Group Can Help

Hamilton Group can help FCA-regulated businesses turn Microsoft 365 security controls into a managed, documented and reviewable environment.

We can assist with:

Microsoft 365 security reviews

Microsoft Entra ID

Conditional Access

MFA

privileged-access reviews

Microsoft Defender

Intune

SharePoint and Teams permissions

Microsoft Purview

sensitivity labels

DLP

audit and retention

backup and recovery

incident-response preparation

operational-resilience planning

security awareness training


The objective is not simply to switch on as many Microsoft features as possible.

It is to make sure the controls match the firm’s actual risks, regulatory requirements and important business services—and that there is evidence they are working.

Visit hgmssp.com or call 0330 043 0069 to discuss a Microsoft 365 security and compliance review.

This article provides general information and is not legal or regulatory advice. Firms should obtain specialist advice appropriate to their permissions, activities and regulatory obligations.