Skip to main content

Strengthening Office 365 Security and Compliance for FCA-Regulated Companies

Media Strengthening Office 365 Security and Compliance for FCA-Regulated Companies

Financial services firms hold some of the most valuable information targeted by cybercriminals. Customer identities, financial records, payment information, investment data, commercially sensitive communications and regulatory documents may all be stored or exchanged through Microsoft 365.

For an FCA-regulated business, securing Office 365 is therefore about much more than protecting email accounts. The Microsoft environment may support customer communications, compliance monitoring, financial-crime controls, record keeping and important business services.

Microsoft 365 provides an extensive collection of security and compliance capabilities. However, purchasing licences does not automatically make an organisation secure or compliant. The controls must be selected, configured, tested, monitored and supported by appropriate business policies.

Why Microsoft 365 Security Matters to FCA-Regulated Firms

The FCA Handbook requires firms to establish and maintain systems and controls appropriate to the nature of their businesses. FCA requirements also refer to robust governance, effective risk-management processes and appropriate safeguards for information-processing systems. 

The FCA’s Financial Crime Guide states that firms are expected to implement systems and controls that minimise the risk of their operations and information assets being exploited. Its information-security guidance also recognises that failures in processing or protecting information can lead to significant operational losses. 

The precise rules that apply will depend on the firm’s permissions, activities, size and regulatory status. However, most FCA-regulated organisations need to demonstrate that technology risks are being actively identified and managed rather than relying on default settings or informal IT processes.

Microsoft 365 Does Not Provide Compliance Automatically

Microsoft 365 can support a regulated company’s security and compliance programme, but it cannot determine the organisation’s regulatory obligations or take responsibility for meeting them.

A firm must still decide:

  • Which information it holds.
  • Where that information is stored.
  • Who should be able to access it.
  • How long records must be retained.
  • How suspicious activity will be detected.
  • Which events must be investigated or reported.
  • How services will continue during disruption.
  • How suppliers and outsourced providers will be governed.

The Microsoft controls should then be configured around these requirements.

This distinction is important. A company could own advanced Microsoft security licences while leaving multifactor authentication inconsistently deployed, permitting excessive administrator access or retaining sensitive files in broadly accessible SharePoint sites.

1. Protect Every User Identity

A compromised Microsoft 365 identity can give an attacker access to email, Teams conversations, SharePoint sites, OneDrive files and other connected systems.

Multifactor authentication should be a fundamental requirement, not an optional protection reserved for senior employees. Microsoft Entra MFA requires users to provide an additional form of verification during the sign-in process, reducing reliance on passwords alone. 

For suitable Microsoft 365 subscriptions, Conditional Access provides more detailed control over how users access company systems. Policies can evaluate signals such as the user, application, device and sign-in conditions before requiring MFA, restricting access or blocking the attempt. 

A stronger identity-security configuration could include:

  • MFA for all employees and external users.
  • Phishing-resistant authentication for administrators and higher-risk roles.
  • Controls for suspicious or high-risk sign-ins.
  • Restrictions on access from unsupported locations.
  • Blocking legacy authentication protocols.
  • Stronger requirements for financial, compliance and administrative applications.
  • Separate accounts for administration and everyday work.
  • Secure emergency-access accounts.

Conditional Access policies should be introduced through a controlled process. Poorly planned policies can block legitimate users or create gaps when exclusions are added without sufficient review.

2. Reduce Privileged Access

Microsoft 365 administrator accounts can change security policies, create users, reset passwords and access sensitive configuration information. An attacker who compromises a highly privileged account may be able to weaken the organisation’s defences before targeting its data.

The principle of least privilege should be applied throughout the environment. Employees and IT providers should receive only the permissions necessary to perform their assigned responsibilities.

For example, someone who manages Exchange Online may not need permanent Global Administrator access. Similarly, a helpdesk employee responsible for user support should not automatically be able to modify organisation-wide security policies.

Privileged access should be:

  • Assigned to named individuals.
  • Separated from normal user accounts.
  • Protected by strong authentication.
  • Recorded and regularly reviewed.
  • Removed when no longer required.
  • Temporary or approval-based where appropriate.
  • Monitored for unusual activity.

Permissions granted to applications and service accounts must also be reviewed. Third-party applications can sometimes retain powerful access long after their original purpose has ended.

3. Strengthen Email Protection

Email remains a common route for phishing, malware, credential theft and payment fraud.

Microsoft Defender for Office 365 can add protections beyond standard spam and malware filtering. Safe Links scans links associated with phishing and other attacks, including supported links in email, Teams and Office applications. Safe Attachments uses a virtual environment to examine attachments for threats such as malware and ransomware before they are delivered. 

FCA-regulated firms should consider configuring:

  • Anti-phishing policies.
  • User and domain impersonation protection.
  • Safe Links.
  • Safe Attachments.
  • Protection for SharePoint, OneDrive and Teams files.
  • External email identification.
  • Controls for automatic forwarding.
  • Alerts for suspicious mailbox activity.
  • Enhanced protection for directors, finance teams and compliance personnel.

Microsoft publishes Standard and Strict preset security configurations for Defender for Office 365. These can provide a useful foundation, although settings should still be tested against the organisation’s operational needs. 

Technical protection must be supported by employee training. Staff should understand how to identify fraudulent payment requests, unexpected MFA prompts, impersonation attempts and messages that direct them to fake Microsoft login pages.

4. Secure the Devices Accessing Microsoft 365

A secure cloud account can still be compromised through an unmanaged or infected laptop.

Microsoft Intune can help organisations manage devices, deploy security settings and evaluate whether devices meet defined compliance requirements. Intune compliance policies are sets of conditions used to assess the configuration of managed devices. 

Conditional Access can then use the device’s compliance status when deciding whether access should be permitted. This allows an organisation to restrict sensitive Microsoft 365 services to devices that meet its requirements. 

A regulated firm might require devices to have:

  • Supported operating systems.
  • Current security updates.
  • Device encryption.
  • Endpoint protection.
  • Secure screen-lock settings.
  • Local firewall protection.
  • Restricted administrator rights.
  • Approved applications.
  • No evidence of rooting or jailbreaking.
  • A minimum acceptable security risk level.

Personally owned devices require particular attention. The organisation should define which services can be accessed from personal devices, whether information can be downloaded and how company data will be removed when access ends.

5. Classify Sensitive Information

A business cannot protect sensitive data consistently unless it understands what that data is.

Microsoft Purview sensitivity labels allow organisations to classify and protect information without necessarily preventing legitimate collaboration. Labels can be designed around the company’s own information-classification structure. 

A financial services firm might use categories such as:

  • Public.
  • Internal.
  • Confidential.
  • Customer confidential.
  • Financial-crime information.
  • Highly restricted.
  • Board or legal material.

Depending on configuration and licensing, labels can apply encryption, restrict access, add visual markings and control how information is shared. Sensitivity labels can also be used with supported Teams, Microsoft 365 groups and SharePoint sites to apply protection settings to collaborative workspaces. 

The classification scheme should be understandable to employees. Too many labels, unclear terminology or complicated exceptions can lead to inconsistent use.

Begin with the organisation’s actual data risks and regulatory requirements rather than simply enabling every available Microsoft option.

6. Introduce Data Loss Prevention

Data Loss Prevention helps reduce the risk of employees accidentally or deliberately sharing sensitive information inappropriately.

Microsoft Purview DLP policies can identify, monitor and protect sensitive information across supported applications, devices and communication methods. 

For example, a DLP policy might identify:

  • Customer financial information.
  • Payment-card information.
  • Identification documents.
  • Bank-account details.
  • Confidential investment information.
  • Special-category personal data.
  • Documents carrying a highly confidential sensitivity label.

Depending on the circumstances, the policy could warn the employee, request a business justification, block the action or alert an authorised compliance or security team.

DLP should normally be introduced in stages. Beginning with monitoring and user warnings allows the organisation to identify false positives and understand genuine working practices before applying stricter restrictions.

Controls should be designed with input from compliance, legal, data protection and operational teams. A purely technical DLP policy may either miss important risks or obstruct legitimate work.

7. Control Teams, SharePoint and OneDrive Sharing

Microsoft 365 makes collaboration straightforward, but poorly controlled sharing can expose information far beyond its intended audience.

Common risks include:

  • Anonymous sharing links.
  • Links that never expire.
  • Excessive access across the organisation.
  • External guests who are no longer involved.
  • Ownerless Teams and Microsoft 365 groups.
  • Sensitive files stored in general-purpose sites.
  • Former employees retaining guest access.
  • Historic projects that remain accessible indefinitely.

Firms should establish clear rules for internal and external collaboration. Sensitive information should be placed in appropriately secured locations rather than relying solely on employees to remember which files should not be shared.

Regular access reviews should examine who can enter important Teams, SharePoint sites and applications. Access should be removed when projects, supplier relationships or employment arrangements end.

8. Maintain Defensible Audit Records

An FCA-regulated organisation may need to investigate suspicious activity, demonstrate how information was handled or reconstruct events after an incident.

Microsoft Purview Audit provides an integrated way to record and search user and administrator activity across supported Microsoft services. Audit information can support security, forensic, compliance, legal and internal investigations. 

The organisation should confirm:

  • Which activities are logged.
  • How long audit records are retained.
  • Which employees can search them.
  • How searches and investigations are authorised.
  • Whether alerts are created for critical events.
  • How audit evidence is preserved.
  • Whether the available retention period meets the firm’s needs.

Microsoft’s auditing capabilities and retention periods vary by licence. Firms should verify that their subscriptions support the investigations and regulatory evidence they may require.

Audit records are only valuable when someone reviews them. Important alerts should be integrated into a defined monitoring and incident-response process.

9. Apply Appropriate Retention and Records Management

Financial firms often hold records that must remain complete, available and retrievable for defined periods. At the same time, keeping every email and document forever can create unnecessary privacy, legal and security risks.

Microsoft Purview Data Lifecycle Management provides tools for retaining necessary information and deleting content that no longer needs to be kept. 

A retention strategy should consider:

  • Regulatory record-keeping obligations.
  • Customer communications.
  • Advice and suitability records.
  • Complaints.
  • Financial-crime investigations.
  • Contracts.
  • Teams messages and meeting content.
  • Employee records.
  • Board and governance documents.
  • Legal holds and active investigations.

The retention structure should be agreed by the relevant legal, compliance and data-protection stakeholders. IT should configure the approved requirements rather than independently deciding how long regulated records must be kept.

Microsoft Purview eDiscovery can be used to identify, review and manage relevant information across supported Microsoft 365 services during investigations and legal matters. 

10. Support Operational Resilience

Email, Teams, SharePoint and other Microsoft 365 services may support important business services. Their security and availability should therefore be considered within the firm’s operational-resilience programme.

The FCA describes operational resilience as a firm’s ability to prevent, adapt and respond to, recover from and learn from operational disruption. Firms within the scope of its operational-resilience rules had until 31 March 2025 to demonstrate that important business services could remain within their impact tolerances. 

That deadline did not mark the end of the work. FCA observations published in March 2026 emphasise continued compliance, mapping, testing and improvement. Firms must maintain testing plans that demonstrate their ability to remain within impact tolerances during severe but plausible disruption. 

Microsoft 365 resilience planning should include:

  • The services and processes that depend on Microsoft 365.
  • The effect of losing email, Teams or SharePoint.
  • Alternative communication arrangements.
  • Administrator-access recovery.
  • Identity-service disruption.
  • Ransomware and account-compromise scenarios.
  • Backup and restoration procedures.
  • Dependency on the IT provider and other suppliers.
  • Testing against the firm’s impact tolerances.

A disaster-recovery document should not exist only to satisfy an audit. It must be tested under realistic conditions.

11. Separate Retention From Backup

Retention and backup serve different purposes.

Retention policies help preserve or delete information according to governance rules. Backup is focused on restoring data following events such as accidental deletion, malicious changes or ransomware.

Microsoft 365 Backup is designed to help organisations restore Microsoft 365 information following malicious or accidental deletion. 

Firms should determine:

  • Which Exchange, SharePoint and OneDrive information requires backup.
  • How quickly information must be recoverable.
  • How long restore points are retained.
  • Who can authorise a restoration.
  • How backup administration is protected.
  • Whether recovery tests are performed.
  • Whether backup arrangements support operational-resilience requirements.

The existence of a backup product is not sufficient evidence of recoverability. Successful restorations should be tested, documented and reviewed.

12. Govern Microsoft and Other Technology Suppliers

Using Microsoft 365 remains a business decision involving third-party risk.

The FCA’s cloud-outsourcing guidance addresses areas such as due diligence, risk management, data security, access, business continuity and exit planning. The guidance remains relevant to firms within its stated scope that use cloud and other third-party IT services. 

The firm should understand:

  • Which services have been outsourced.
  • What data each supplier processes.
  • Where responsibilities are divided.
  • Which subcontractors are involved.
  • How incidents will be communicated.
  • What assurance reports are available.
  • Whether access and audit requirements can be met.
  • How services and data could be transferred or recovered.
  • What happens if the supplier fails.

New FCA rules covering operational-incident and material third-party reporting were finalised in March 2026 and are due to come into force on 18 March 2027. Firms within scope should use the preparation period to understand their arrangements, reporting responsibilities and third-party register requirements. 

An outsourced IT provider can help implement and operate controls, but the regulated firm retains responsibility for understanding and governing the arrangement.

13. Prepare for Security-Incident Reporting

A Microsoft 365 incident may trigger several reporting and communication obligations.

The organisation needs a documented process for deciding:

  • What constitutes a security or operational incident.
  • Who leads the response.
  • When compliance, senior management and legal advisers are involved.
  • When the FCA must be notified.
  • Whether the ICO, law enforcement or other bodies must be contacted.
  • How affected customers and partners will be informed.
  • What evidence must be preserved.

The FCA provides guidance on reporting operational incidents and notes that data breaches may also require reporting to the ICO. Where required under UK GDPR, personal-data breaches must generally be reported to the ICO within 72 hours of awareness, where feasible. 

The incident plan should contain current contact details, reporting responsibilities, decision-making authority and practical instructions for operating when normal Microsoft 365 communications are unavailable.

14. Review Microsoft Secure Score—But Do Not Treat It as Compliance

Microsoft Secure Score measures the organisation’s Microsoft security posture according to recommended improvement actions. A higher score indicates that more of those actions have been completed. 

It can help firms identify missing controls and track technical improvements over time. However, it is not an FCA compliance certificate, penetration test or complete risk assessment.

Recommendations should be evaluated according to:

  • The firm’s risks.
  • Regulatory obligations.
  • Operational requirements.
  • Existing compensating controls.
  • Licensing.
  • User impact.
  • Technical dependencies.

The objective should not be to achieve the highest possible score without question. The objective is to implement appropriate, tested and documented controls.

A Practical Security and Compliance Checklist

An FCA-regulated Microsoft 365 environment should generally be reviewed for:

  • MFA coverage across all users.
  • Phishing-resistant authentication for privileged accounts.
  • Conditional Access configuration.
  • Administrator-role assignments.
  • Guest and external-user access.
  • Defender for Office 365 policies.
  • Managed-device compliance.
  • SharePoint, Teams and OneDrive permissions.
  • Sensitivity labels.
  • DLP controls.
  • Retention and records-management policies.
  • Audit configuration and retention.
  • Backup and recovery testing.
  • Incident-response procedures.
  • Supplier due diligence and exit planning.
  • Operational-resilience mapping and scenario testing.
  • Licence suitability.
  • Employee security training.
  • Evidence of regular reviews and management oversight.

Not every Microsoft capability is included with every subscription. Licensing, regulatory scope and technical requirements should be confirmed before controls are implemented.

How Hamilton Group Can Help

Microsoft 365 can support a strong security and compliance programme, but only when its controls are aligned with the firm’s risks and regulatory responsibilities.

Hamilton Group can help FCA-regulated companies review and strengthen their Microsoft environments through:

  • Microsoft 365 security assessments.
  • Microsoft Entra and Conditional Access configuration.
  • Administrator and permission reviews.
  • Microsoft Intune device management.
  • Microsoft Defender deployment.
  • SharePoint and Teams access reviews.
  • Microsoft Purview sensitivity labels and DLP.
  • Audit and retention configuration.
  • Backup and recovery planning.
  • Incident-response preparation.
  • Operational-resilience support.
  • Security awareness training.
  • Ongoing monitoring and IT support.

To arrange a review of your Microsoft 365 environment, contact Hamilton Group on 0330 043 0069 or visit hgmssp.com.

This article provides general information and should not be treated as legal or regulatory advice. Firms should obtain specialist advice based on their specific permissions, activities and obligations.