Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Cybersecurity whitepaper | Architects

Microsoft 365 Security for Architecture Firms

Practical steps to protect email, Teams, and project files in Microsoft 365

  • Published September 25, 2026
  • 4 min read

Most architecture firms run the business side of every project through Microsoft 365. Email, Teams, SharePoint, and OneDrive hold proposals, contracts, fee letters, and years of client correspondence. That is why Microsoft 365 security deserves the same care you give your drawings, because one stolen login can expose all of it.

Why attackers target design firm accounts

Architecture firms trade email with owners, contractors, engineers, and consultants all day. As a result, attackers know your staff expects attachments and links from outside the firm. A fake file share notice or a lookalike consultant address does not look unusual in that flow.

In addition, a compromised mailbox gives an attacker more than email. It often opens OneDrive, SharePoint sites, and Teams channels where project files live. From there, they can study billing habits, copy design work, or send convincing messages to your clients.

Start with identity: MFA and sign-in rules

First, require multifactor authentication for every account. That includes principals, interns, shared mailboxes that allow sign-in, and the admin accounts your IT provider uses. Also, favor app-based prompts or hardware keys over text messages when you can.

Next, block legacy sign-in methods that skip MFA. Older email protocols still work in many tenants, so attackers try them first. Then use conditional access rules to limit risky sign-ins, for example logins from countries where nobody at the firm works.

Finally, separate admin rights from daily work. The person who approves timesheets should not browse the web with a global admin account. Instead, give admins a separate login that they use only for administration.

Control sharing in SharePoint, OneDrive, and Teams

Design teams share constantly, so sharing settings matter. However, the defaults in many tenants let anyone create links that work for anyone who has them. Those links travel through forwarded emails and never expire.

Instead, set external sharing to named guests where possible. Add expiration dates to links, and review guest accounts after each project closes. That way, a consultant from a finished job does not keep access to your current work.

Also, structure Teams and SharePoint by project or client. When permissions follow the project, it becomes easy to see who has access and why. As a result, cleanup at project closeout takes minutes instead of days.

A Microsoft 365 security checklist for firm leaders

You do not need to manage the settings yourself. Still, you should know whether these basics are in place. Ask your IT team or provider to confirm each item:

  • The tenant enforces MFA for every user, with no permanent exceptions.
  • The tenant blocks legacy authentication.
  • Admins use accounts that stay separate from daily user accounts.
  • External sharing uses named guests and expiring links.
  • Someone reviews guest accounts at every project closeout.
  • Rules stop automatic forwarding to outside addresses.
  • Audit logging stays on, with logs kept for review.
  • A separate backup covers email, OneDrive, SharePoint, and Teams.

Watch for the quiet signs of compromise

Account takeovers rarely announce themselves. Instead, attackers create inbox rules that hide replies, forward copies of messages, or move invoices to obscure folders. They may also register their own device for MFA so they can return later.

So someone needs to watch sign-in logs and alerts, not just collect them. For example, a login from a new country followed by a new forwarding rule is a strong warning sign. Because these signals are easy to miss, many firms rely on a monitoring service that reviews them around the clock.

Training is part of Microsoft 365 security too. When staff know how to report a strange login prompt or an unexpected MFA request, you catch problems earlier. In addition, a simple reporting button in Outlook makes that habit easy.

Back up Microsoft 365 data on your own terms

Microsoft keeps the service running, but it does not promise to restore every file your staff deletes or every mailbox an attacker wipes. Retention settings help, although they are not the same as a true backup.

Therefore, use a third-party backup that copies mail, OneDrive, SharePoint, and Teams data to separate storage. Then test a restore of a real project folder at least a few times a year. That test tells you how long recovery actually takes.

How WEBIT helps

WEBIT baselines every client to the CIS Controls by default, and we apply that same discipline to Microsoft 365 settings. Our Security Advanced add-on adds Microsoft 365 threat detection and response, email security, Microsoft 365 backup, and security awareness training.

We also run monthly or quarterly health assessments and review the findings with you. If you want to see how this fits a design practice, visit our architecture firm IT page or learn more about our cybersecurity services.

Key takeaways

  • Enforce MFA for every account and block legacy sign-in methods.
  • Use named guests and expiring links for outside collaborators.
  • Review guest access at every project closeout.
  • Monitor sign-ins and inbox rules, because takeovers are quiet.
  • Back up Microsoft 365 data separately and test restores.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Architects IT services

See how WEBIT supports architects organizations across Chicagoland.

Explore Architects IT →

More Architects whitepapers

Browse the full library of guides for your industry.

All Architects whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.