Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Cybersecurity whitepaper | Engineering

Microsoft 365 Security for Engineering Firms

The tenant settings that protect project email, files, and client sharing

  • Published September 25, 2026
  • 4 min read

Most engineering firms now run email, file sharing, and project chat through Microsoft 365. That makes the platform a primary target, because one stolen password can expose proposals, drawings, and client correspondence. Strong Microsoft 365 security depends less on buying new tools and more on configuring the ones you already have.

Why Microsoft 365 security matters for design firms

Engineering work is highly collaborative. Project teams share folders with clients, architects, contractors, and subconsultants.

They also use shared mailboxes for bids, RFIs, and submittals. Each connection is useful, but each one also widens the door an attacker can use.

Attackers know this. A compromised mailbox lets them read ongoing project threads, learn who approves invoices, and send convincing messages from a trusted address. As a result, a single account takeover can spread to clients and partners quickly.

Lock down sign-ins first

Identity is the front door to the tenant. Therefore, start by requiring multifactor authentication for every user, including principals and part-time staff. Prefer app-based prompts or hardware keys over text messages when possible.

Next, turn off legacy authentication protocols. Older mail clients and some scanners still use them, and they cannot enforce multifactor prompts. If a plotter or scanner still needs to send email, give it a limited, dedicated method instead.

Then use conditional access if your licenses include it. For example, you can block sign-ins from countries where you have no staff, or require a managed device to open project files. These rules stop many attacks before a password even matters.

Control administrator access

Many small firms have too many global administrators. Often a founder, an office manager, and a former IT contractor all hold full rights. That spreads risk across accounts that nobody watches closely.

Instead, keep global administrator rights to two or three dedicated accounts that nobody uses for daily email. Assign narrower roles, such as user or billing administrator, for routine tasks. Also review those assignments whenever someone changes roles or leaves.

Manage sharing with clients and subconsultants

SharePoint and Teams make external sharing easy. However, default settings may let anyone create links that never expire. Over time, a firm can end up with hundreds of open links to old project folders.

So set sharing policies that match how your firm works. For instance, you might allow sharing only with signed-in guests, set expiration dates on links, and restrict anonymous links entirely. In addition, review guest accounts on a schedule and remove guests once a project closes.

A Microsoft 365 configuration checklist

  • Require multifactor authentication for all users and administrators.
  • Disable legacy authentication and basic protocols that bypass multifactor prompts.
  • Limit global administrators to a small number of dedicated accounts.
  • Block automatic forwarding of email to outside addresses.
  • Set expiration and permission defaults on external sharing links.
  • Turn on unified audit logging and confirm how long the tenant keeps logs.
  • Enable safe link and attachment scanning for email and Teams.
  • Back up mailboxes, OneDrive, SharePoint, and Teams with a separate service.

Watch for signs of compromise

Configuration reduces risk, but it does not remove it. You also need someone watching for suspicious activity. Warning signs include new inbox rules that move or delete messages, sign-ins from unusual locations, and sudden bulk file downloads.

Inbox rules deserve special attention. Attackers often create rules that hide replies from a client or vendor, so the real user never sees them. When those rules appear, treat the account as compromised until you confirm otherwise.

Also watch for new app consents. Attackers sometimes trick users into granting a malicious app access to mail and files, which keeps working even after a password reset.

Remember that retention is not backup

Microsoft keeps your data available, but its retention features do not work like a full backup. If a user deletes a project folder, or ransomware encrypts synced files, recovery options may be limited. A separate backup service gives you point-in-time copies that you control.

This matters for engineering firms because project files have long lives. You may need a correspondence thread or a design revision long after closeout, especially if a claim arises.

How WEBIT helps

WEBIT configures and monitors Microsoft 365 tenants for engineering firms, starting with identity, sharing, and administrator controls. Our Security Advanced add-on includes Microsoft 365 threat detection and response, email security, Microsoft 365 backup, and security awareness training. We also offer Duo MFA for firms that want consistent prompts across cloud and on-premises systems.

Every client gets a named Client Success Manager and regular health assessments, so settings do not drift over time. Explore our cloud infrastructure services or contact us to review your tenant.

Key takeaways

  • Strong Microsoft 365 security starts with multifactor authentication and no legacy sign-ins.
  • Keep global administrator rights to a few dedicated accounts.
  • Set sharing and guest policies that match how project teams work.
  • Monitor for suspicious inbox rules, app consents, and unusual sign-ins.
  • Use a separate backup, because retention is not the same as recovery.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Engineering IT services

See how WEBIT supports engineering organizations across Chicagoland.

Explore Engineering IT →

More Engineering whitepapers

Browse the full library of guides for your industry.

All Engineering whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.