Cloud Security for Law Firms: What to Monitor Post-Migration
Moving to the cloud does not finish your security work. For most law firms, the post-migration period is when real exposure actually increases. Permissions get set up quickly during the transition. Monitoring gets deferred until after things stabilize. Settings default to open while staff are getting established. Those gaps do not close themselves, and attackers know the weeks after a migration are when firms are most likely to have something misconfigured with nobody watching it.
Why This Window Is Riskier Than the Migration Itself
The migration gets attention. Firms bring in IT resources, test connectivity, verify data integrity, and make sure attorneys can access what they need. What gets less attention is everything that happens in the weeks and months after, when the project team has moved on and daily monitoring habits have not formed yet.
A 2023 ABA cybersecurity survey found that 29% of law firms had reported a security breach at some point, and firms in the 10-to-49 attorney range were the most frequently targeted. That population is also the one most likely to have completed a cloud migration recently, because many of those firms are moving off aging on-premises infrastructure for the first time. The timing is not coincidental.
When a firm moves its email and document systems to Microsoft 365, it also exposes those systems to credential-based attacks at a scale that did not exist before. On-premises Exchange had some natural obscurity; a publicly accessible Microsoft 365 tenant does not. Credential stuffing tools target M365 sign-in endpoints constantly. If MFA is inconsistently enforced or audit logging was never turned on, that exposure is invisible until something goes wrong.
For context on what that exposure looks like when it becomes an incident, see Ransomware and Legal Malpractice: The Risk Law Firms Miss.
What Actually Changes After the Migration
The security model changes more than most firms expect. On-premises environments have a clear perimeter: someone inside the office or on the VPN gets access, everyone else does not. Cloud environments do not work that way. Access is identity-based, not location-based. The perimeter is effectively wherever your credentials are.
That shift has practical consequences. A staff member who reuses a password from a breached site now represents a direct path into your firm's email and document systems from anywhere in the world. An admin account created during migration with broad permissions and never reviewed is an open door. External sharing enabled temporarily to test a client portal and then forgotten is an ongoing exposure.
None of those are exotic attack techniques. They are the most common ways cloud environments at professional services firms get compromised, and they all share one thing: they persist quietly until someone looks for them.
What to Monitor Post-Migration
Most of this monitoring is built into the platforms law firms are already running. The issue is that it does not arrive configured, and it is not organized into anything actionable without someone deliberately setting it up.
Sign-in logs and failed authentication attempts. Microsoft 365's audit logs capture every authentication event. Failed login attempts, particularly those from unfamiliar locations or unusual hours, deserve regular review. A spike in failed logins against one account is often a credential stuffing attempt in progress. Most firms have no visibility into this at all post-migration.
MFA enforcement status. Multi-factor authentication being required at setup and MFA being enforced for every account at all times are different things. Check which accounts have MFA enabled versus which ones have it listed as registered but not enforced through conditional access policy. In post-migration environments, there are almost always a handful of accounts that slipped through.
Privileged account activity. Global admin accounts created during migration are high-value targets. Review who has admin-level access, whether those accounts are separated from daily-use accounts, and what those accounts have been doing. A 25-attorney Indianapolis firm we worked with found three active global admin accounts post-migration that nobody had reviewed since go-live. One belonged to a contractor who had finished his work six weeks earlier.
External sharing and guest access. SharePoint and Teams both default to fairly permissive external sharing settings in many migration configurations. Review what is shared externally, with whom, and whether those sharing links are still active. Files shared temporarily during migration often stay shared indefinitely.
Audit log retention. Microsoft 365 defaults to 90-day audit log retention on standard licenses. If your firm is involved in litigation, subject to bar or regulatory requirements around record-keeping, or would need to reconstruct an incident timeline months later, 90 days is not enough. This is a configuration decision that needs to be made deliberately, not defaulted into.
Conditional access policies. These policies define which users, from which locations, on which devices, can access what. Post-migration, many firms have conditional access partially configured because it was being set up during a busy transition window. A full review of what is actually covered versus what is assumed to be covered is worth doing in the first 60 days after go-live.
How an MSP Helps Law Firms Stay Ahead of This
The monitoring above requires both technical setup and someone to act on the output. That is the part most law firms do not have in-house. Not the tools, but the process for doing something when the tools surface a problem.
An MSP managing a law firm's Microsoft 365 environment typically configures centralized log collection so sign-in anomalies, admin activity, and external sharing changes generate alerts rather than sitting in a dashboard nobody checks. Alert fatigue is real, so good work here means tuning alerts to what actually matters for a law firm, not everything the platform can technically surface.
There is also a value in pattern recognition. MSPs working in the legal sector have handled the specific combination of issues that post-migration law firm environments generate: the admin account a departing partner still has access to, the client data shared via a guest link that was never closed, the audit gap that complicates incident response. Knowing where to look speeds up both detection and remediation significantly.
Read: IT Services and Cybersecurity for Law Firms
Best Practices for the Post-Migration Period
Schedule a 60-day security review, separate from the operational stability check. Most firms do a 30-day check to confirm things work. Security is a different review: are the right controls on, is monitoring configured, are permissions what they should be? If you only did the operational check, schedule the security review now.
Audit privileged accounts before anything else. Global admin accounts created during migration often have more access than anyone realizes. Run the report, review who is on the list, and remove or restrict anyone who does not need that level of access on an ongoing basis.
Configure audit log retention deliberately. Decide what your firm needs based on litigation exposure and bar requirements, then set it. Do not leave it at the platform default.
Test your conditional access policies with a realistic scenario. Policies that look complete on paper sometimes have gaps in practice. Have your IT provider test what a user actually experiences logging in from an unmanaged device or an unusual location, not just review the policy settings in the admin console.
Read: Core Managed Cyber Risk Assessment
Frequently Asked Questions
How long after a cloud migration should a law firm expect elevated security risk?
The highest-risk period is typically the first 90 days, but misconfigured settings and unreviewed permissions can persist much longer if no one is actively looking. Firms that do a structured security review at the 60-day mark and again at six months are significantly better positioned than those that treat the migration as complete once attorneys can access their files.
Is Microsoft 365 secure enough for a law firm's sensitive client data?
The platform is capable of meeting law firm security requirements, but it does not arrive configured that way. Default settings in M365 are calibrated for accessibility, not maximum security. A firm using M365 with default settings has a different risk profile than one with conditional access policies, MFA enforcement, audit logging, and external sharing controls properly configured. The platform is the starting point, not the destination.
What is conditional access, and why does it matter for law firms?
Conditional access policies in Microsoft 365 let you define rules about when and how users can access resources: from which locations, on which devices, at which times, and with which authentication requirements. For a law firm, this means you can require that access to client files only happens from managed devices with MFA verified, block access from countries where your firm has no business, and require additional verification for accounts with elevated permissions. Without these policies, any valid credential from anywhere in the world gets the same access.
What should a law firm do if it suspects a breach of its cloud environment?
Isolate the affected accounts first. That means disabling sign-in for any account suspected of compromise and revoking active sessions in the Microsoft 365 admin center. Contact your MSP or IT provider immediately; time matters in containing a cloud breach because the attacker may still be active. Do not attempt to investigate by logging into the affected account. Preserve audit logs before taking any action that might overwrite them. If client data is involved, loop in outside counsel early, because bar notification obligations may apply and the timeline for that analysis starts at discovery, not at the end of the investigation.
Protecting your business starts with the right partner. Core Managed helps companies secure their data, scale efficiently, and stay compliant so you can focus on running the business. Give us a call at 888-890-2673 or contact us to schedule a conversation.
For more on how MSPs turn IT challenges into competitive advantages, read our feature in the Atlanta Business Chronicle.