Microsoft 365 for accountancy firms is no longer just the place the email lives. It is where the client files sit, where the payroll instructions arrive, where the engagement letters are signed, and where an attacker who wants a tax refund diverted will go first. For most UK practices the Microsoft 365 for accountancy tenant now holds more regulated client data than the practice management system does, and it is administered by whoever happened to set it up.
This is the security checklist for that tenant. Twenty Microsoft 365 for accountancy controls, grouped into six domains, each with a ten-minute evidence test you can run yourself and the licence that actually delivers it. It is written for UK practices between two and two hundred people, and it assumes a Microsoft 365 for accountancy tenant already exists rather than that you are building one.
Three fixed 2026 deadlines shape the order. HMRC switches on multi-factor authentication across every agent account between 28 September and 15 October 2026. Companies House closes its identity verification transition on 18 November 2026. And the Cyber Essentials question set moved to Danzell on 26 April 2026, with MFA on cloud services now an outright fail.
None of that is optional and none of it is far away. What follows is the shortest defensible path through it, written as one Microsoft 365 for accountancy checklist rather than a pile of vendor articles. If you want the wider estate view rather than the tenant view, the companion piece on IT support for accountancy practices covers hardware, connectivity and supplier management, and the Microsoft 365 security checklist for property management companies and the hospitality version of this tenant checklist cover the same controls for two other regulated sectors.
Table of contents
- Why Microsoft 365 for Accountancy Practices Is Now a Regulated Control Surface
- What Makes Microsoft 365 for Accountancy Different From Any Other Sector
- How to Use This Microsoft 365 for Accountancy Checklist
- Microsoft 365 for Accountancy, Domain 1: Identity and Access
- Microsoft 365 for Accountancy, Domain 2: Email and the Client Money Channel
- Microsoft 365 for Accountancy, Domain 3: Devices and Endpoints
- Microsoft 365 for Accountancy, Domain 4: Client Data and Retention
- Microsoft 365 for Accountancy, Domain 5: Monitoring and Recovery
- Microsoft 365 for Accountancy, Domain 6: Governance and Ownership
- The HMRC Agent MFA Rollout and Your Microsoft 365 for Accountancy Tenant
- What Microsoft 365 for Accountancy Does Not Cover
- What Microsoft 365 for Accountancy Actually Costs
- A 90-Day Plan for Microsoft 365 for Accountancy
- Turning Microsoft 365 for Accountancy Controls Into Evidence Clients Accept
- Common Mistakes in Microsoft 365 for Accountancy Deployments
- Frequently Asked Questions About Microsoft 365 for Accountancy
- References
Why Microsoft 365 for Accountancy Practices Is Now a Regulated Control Surface
Microsoft 365 for a two-partner practice looks nothing like the same product in a fifty-seat firm, but the regulatory exposure is identical in kind. The data inside a Microsoft 365 for accountancy tenant is client money, client identity and client tax position, and the regulator does not scale its expectations to your headcount.
What a practice actually holds inside the tenant
Walk any UK practice through what a Microsoft 365 for accountancy tenant genuinely stores in Exchange Online, SharePoint and OneDrive and the list is longer than the partners expect. Bank details for payroll runs. Passport scans and utility bills gathered for anti-money laundering checks. National Insurance numbers, unique taxpayer references, and in many firms the client’s own HMRC correspondence forwarded by email. Microsoft 365 for accountancy work concentrates all of it into one identity boundary.
| What the practice holds | Where it usually lives | What sets the retention |
|---|---|---|
| AML customer due diligence evidence | SharePoint client folder, or a mailbox | MLR 2017 regulation 40 — five years |
| Companies House identity check records | SharePoint, practice software, or paper | ACSP duty — seven years |
| Tax computations and supporting records | Practice software plus a SharePoint copy | Client’s own record-keeping obligation |
| Payroll instructions and bank details | Shared payroll mailbox | Employment and payroll obligations |
| Engagement letters and fee disputes | Partner mailboxes and OneDrive | Limitation period and PII insurer |
| HMRC agent correspondence | Shared tax mailbox | Practice policy — usually six years |
The three deadlines that make 2026 different
Practices have been told to improve Microsoft 365 for accountancy security for years without a date attached. In 2026 there are three dates, and all of them land inside a single quarter of each other.
| Deadline | Date | What it forces |
|---|---|---|
| HMRC agent MFA, blanket activation | 28 September to 15 October 2026 | Every ASA and OSA sign-in needs a second factor |
| Companies House identity verification | 18 November 2026 | Existing directors, PSCs and LLP members verified |
| Cyber Essentials Danzell question set | Live since 26 April 2026 | MFA on cloud services, updates inside 14 days |
| Microsoft 365 admin centre MFA enforcement | Completed 9 February 2026 | Admin sign-in already blocked without MFA |
| SMTP AUTH basic authentication retirement | End of December 2026 | Scan-to-email and app senders must move |
The regulator has already priced a missing MFA
In April 2025 the Information Commissioner’s Office fined the law firm DPP Law £60,000 after attackers brute-forced an infrequently used administrator account that had no multi-factor authentication on it, moved laterally, and took 32GB of data. The firm only learned of the theft when the National Crime Agency told it client information had appeared on the dark web. Nothing about that case is specific to law. Substitute a dormant admin account in a Microsoft 365 for accountancy tenant and the facts read the same.
That was not an outlier year. The ICO issued 28 monetary penalty notices in 2025, its highest annual total since UK GDPR came into force, and the average penalty moved from roughly £150,000 to over £2.8 million as the regulator shifted from many small fines to fewer, heavier ones. Capita was fined £14 million on 15 October 2025. A practice that runs Microsoft 365 for accountancy without documented identity controls is carrying that risk knowingly.
The sector-wide numbers, and where small firms actually sit
The government’s Cyber Security Breaches Survey, published on 30 April 2026, found 43% of UK businesses had experienced a breach or attack in the previous twelve months — roughly 612,000 organisations. Phishing was the most common vector at 38% of businesses and the most disruptive for 69% of those affected. Only 47% of businesses use any form of two-factor authentication, only 25% have an incident response plan, and only 5% hold Cyber Essentials — three gaps that a Microsoft 365 for accountancy baseline closes at once.
The size split is the number that matters when scoping Microsoft 365 for accountancy work, because it shows the risk does not fall away when the firm is small.
What Makes Microsoft 365 for Accountancy Different From Any Other Sector
Every business wants its email secured. A practice has three characteristics that change which Microsoft 365 for accountancy controls matter first, and they are the reason a generic hardening guide leaves the biggest holes open.
The HMRC agent account is the crown jewel, and it is not yours
Criminals have worked out that the highest-value target in UK tax is not a taxpayer but an agent. Compromise one agent gateway and you can file fraudulent VAT and Self Assessment returns across an entire client list and redirect the repayments, whatever the Microsoft 365 for accountancy tenant behind it looks like. HMRC’s own response tells you how serious it has become: multi-factor authentication is being switched on across every agent account during 2026, having previously been optional.
The scale of the underlying problem is public. HMRC disclosed to the Treasury Select Committee on 4 June 2025 that organised criminals had used phishing to compromise around 100,000 PAYE accounts — about 0.2% of that service’s user base — and extract £47 million in fraudulent repayments. The committee criticised HMRC for the way it disclosed the incident. Separately, HMRC received more than 170,000 scam referrals in the twelve months to 31 July 2025, of which more than 47,000 involved fake tax refund claims.
A Microsoft 365 for accountancy tenant cannot protect the agent account directly. It can protect the mailbox where the credentials were reset, the device where they are typed, and the staff member being socially engineered into reading out a code. That is the whole point of getting Microsoft 365 for accountancy practices right.
Shared credentials are normal here, and they break every identity control
Most Microsoft 365 for accountancy tenants carry at least one shared HMRC login, one shared payroll mailbox and one generic info@ address that four people watch. HMRC’s guidance for the MFA rollout acknowledges this directly: firms using a shared login and an authenticator app will need to distribute the seed key so each employee generates the same codes, and every account needs at least two administrators because nobody can reset their own MFA.
That is a workable answer for HMRC. Inside a Microsoft 365 for accountancy tenant it is not, and the checklist below treats every shared identity as a control failure to be closed rather than a fact of life.
Why the tax calendar concentrates Microsoft 365 for accountancy risk
Microsoft 365 for accountancy risk is not evenly spread across the year. Self Assessment peaks into 31 January, corporation tax and payroll year end cluster around early April, and both windows are exactly when staff are tired, working late and least likely to question an email about a changed bank account. Attackers know the UK tax calendar as well as you do. Any Microsoft 365 for accountancy deployment should assume the worst phishing week of the year is the last week of January.
How to Use This Microsoft 365 for Accountancy Checklist
Twenty controls, six domains. Read the domain, run the Microsoft 365 for accountancy evidence test, record the result. The point is not to score well, it is to produce a Microsoft 365 for accountancy evidence pack you can hand to a client’s procurement team, a Cyber Essentials assessor or a professional indemnity insurer without rewriting it first.
The ten-minute evidence test behind every control
Every control below carries a test that a competent person can complete in about ten minutes using the Microsoft 365 admin centre, the Entra admin centre, the Defender portal or the Purview portal. If a Microsoft 365 for accountancy control cannot be evidenced in ten minutes, it is not implemented — it is believed. Those are different things, and the difference is what an assessor is paid to find.
Licence honesty about Microsoft 365 for accountancy
Roughly half of the controls in this Microsoft 365 for accountancy checklist need Business Premium or better, and no amount of configuration substitutes for the licence. There is no configuration trick that produces conditional access on a Business Standard licence. Read the licence table in the costs section before you promise a partner meeting that everything below is free.
| Domain | Controls | What it protects |
|---|---|---|
| 1. Identity and access | 1 to 5 | Who can sign in, from where, as whom |
| 2. Email and the money channel | 6 to 9 | Payment instructions and HMRC correspondence |
| 3. Devices and endpoints | 10 to 12 | Laptops, phones and unmanaged home machines |
| 4. Client data and retention | 13 to 16 | Confidentiality and statutory record keeping |
| 5. Monitoring and recovery | 17 to 19 | Knowing what happened, and getting it back |
| 6. Governance | 20 | Whether any of the above survives next year |
Microsoft 365 for Accountancy, Domain 1: Identity and Access
Identity is where practices lose. Every incident described earlier in this Microsoft 365 for accountancy guide started with a credential rather than a clever exploit, and every control in the other five domains assumes this one already holds.
Control 1: Multi-factor authentication on every account, with no exclusions
Not “on for partners”. Not “on except the two accounts that broke last time”. Every licensed user, every administrator, every account that can read a mailbox. Cyber Essentials under the Danzell question set treats missing MFA on a cloud service as an automatic fail, which means a single excluded account costs the whole certificate. Microsoft has already enforced this on its own side: multi-factor authentication became mandatory for the Microsoft 365 admin centre on 9 February 2026, after the Azure, Entra and Intune portals were enforced through 2024 and early 2025.
Prefer phishing-resistant methods where you can. Passkeys and FIDO2 security keys defeat the code-relay attacks that authenticator app prompts do not, and they are free with any Business licence. Where a code-based method is unavoidable, an authenticator app beats SMS, which is exactly the order HMRC recommends for its own agent rollout.
Evidence test: In the Entra admin centre, open Users, add the “MFA status” column, sort by it, and screenshot the count of accounts with no method registered. The correct answer is zero.
Control 2: A conditional access baseline, not just security defaults
Security defaults are better than nothing and worse than a written policy. A practice running Microsoft 365 for accountancy work needs at least four conditional access policies: require MFA for all users, require MFA for all administrators with no exclusions, block legacy authentication protocols outright, and require compliant or hybrid-joined devices for access to SharePoint and Exchange. Add a country restriction if the practice never works outside the UK and Ireland, and add a sign-in frequency limit for privileged roles.
One free win worth knowing about: Microsoft-managed conditional access policies now block device code flow by default in tenants that have not used it in the previous 25 days. Device code phishing has been used against professional services firms repeatedly, and most practices have no legitimate use for the flow at all.
Evidence test: Entra admin centre, Protection, Conditional Access. Export the policy list. Every policy should be in “On” state, not “Report-only”, and the named exclusions should be one documented break-glass account and nothing else.
Control 3: Kill legacy authentication and plan the SMTP AUTH move
Legacy authentication protocols bypass MFA entirely. They are also how the scan-to-email function on the office multifunction printer works, which is why so many practices leave them switched on. Basic authentication for SMTP AUTH remains usable until the end of December 2026, after which Microsoft disables it — so this is a dated project, not a preference.
Inventory every device and application that sends mail through the Microsoft 365 for accountancy tenant: the printer, the practice management system’s email-out function, the payroll software’s payslip distribution, the portal that notifies clients a return is ready for approval. Each one needs either OAuth or a high-volume email path before the deadline.
Evidence test: In the Entra sign-in logs, filter Client app to the legacy authentication clients and set the range to the last 30 days. Any result is a device you have not inventoried yet.
Control 4: Separate, named administrator accounts
The DPP Law penalty turned on an infrequently used administrator account with no second factor. The pattern in a small Microsoft 365 for accountancy tenant is identical: the partner who set it up six years ago still holds Global Administrator on the same account they use for daily email, and there is one more admin account that nobody has signed into since the migration.
Fix it in three moves. Give every administrator a separate cloud-only admin identity with no mailbox and no licence. Reduce Global Administrator to two people and use least-privilege roles for everything else. Keep exactly one break-glass account, excluded from conditional access, with a long random password stored offline and its sign-ins alerted on.
Evidence test: Entra, Roles and administrators, Global Administrator. Count the members. If it is more than two, or if any of them has a mailbox attached, the control has failed.
Control 5: Shared and generic mailboxes with no interactive sign-in
Shared credentials are the practice-specific Microsoft 365 for accountancy failure. The payroll@ mailbox with a password four people know, the info@ account that also happens to be a licensed user, the “practice” login used for the client portal. Every one of them is an identity with no owner, and none of them can be meaningfully protected by MFA.
The Microsoft 365 for accountancy answer is a shared mailbox — an unlicensed object with sign-in blocked, accessed by named users who each have their own MFA. If a workflow genuinely needs a shared HMRC credential because HMRC only issues one, that credential belongs in a password manager with an audit trail, not in a mailbox rule or a note on the intranet.
Evidence test: In the Microsoft 365 admin centre, list shared mailboxes and check each has “Sign-in blocked” set. Then list licensed users and challenge any that are not a named human being.
Fifteen of those 49 identities — shared plus privileged — are the ones an attacker on a Microsoft 365 for accountancy tenant actually wants, and they are the ones a headcount-based licence review never looks at.
Microsoft 365 for Accountancy, Domain 2: Email and the Client Money Channel
Email is where Microsoft 365 for accountancy tenants authorise money to move. Not directly, but close enough: a payroll file, a bank detail change, a refund destination, a supplier’s new account number. These four controls are about that channel specifically.
Control 6: Anti-phishing policy with impersonation protection turned on
The default anti-spam configuration does not protect against the attack that hits Microsoft 365 for accountancy tenants hardest: a message that appears to come from a partner, or from a client’s finance director, asking for something plausible. Impersonation protection in Defender for Office 365 lets you name the people worth impersonating — partners, the practice manager, the payroll lead — and the domains worth protecting, including your largest clients.
Turn on mailbox intelligence and first-contact safety tips at the same time. The tip that says “you do not usually receive email from this address” is the single cheapest intervention available, because it puts the warning in front of the person at the moment of decision rather than in a report nobody reads.
Evidence test: Defender portal, Email and collaboration, Policies and rules, Anti-phishing. Open the policy and confirm the protected users list is populated and impersonation protection is enabled, not just present.
Control 7: Safe Links and Safe Attachments across mail, Teams and SharePoint
A link that was clean when it was delivered is not necessarily clean when it is clicked three days later, which is exactly the window a January-deadline mailbox creates. Safe Links rechecks at click time; Safe Attachments detonates the file before it lands. Both extend to Teams, SharePoint and OneDrive, which matters because client documents arrive by all three.
Evidence test: Defender portal, Policies and rules, Safe Links. Confirm a policy exists that covers all recipients and that the Teams, SharePoint and OneDrive toggles are on.
Control 8: Block auto-forwarding, and audit inbox rules weekly
Business email compromise against Microsoft 365 for accountancy tenants usually has a quiet phase. The attacker signs in, creates an inbox rule that moves anything mentioning “invoice”, “bank” or “remittance” to a rarely opened folder, and waits for a payment run. The theft happens weeks later, and the practice’s own mail client hides the evidence.
Block automatic external forwarding at the tenant level, then alert on new inbox rule creation. Both are configuration rather than licence for the forwarding block; the alerting side is where a Business Premium tenant earns its money.
Evidence test: Defender portal, anti-spam outbound policy — confirm automatic forwarding is set to Off rather than Automatic. Then run a mailbox rule report across all mailboxes and read it. Any rule forwarding externally or deleting on receipt needs an owner’s explanation today.
Control 9: SPF, DKIM and DMARC on every domain you own
Practices running Microsoft 365 for accountancy routinely own three or four domains: the main one, a legacy one from a merger, a vanity redirect and one bought defensively. The unused ones are the dangerous ones, because an unprotected domain that resolves is a free identity for anyone sending on your behalf.
Publish SPF, sign with DKIM, and move every domain to a DMARC reject policy in stages — monitor, then quarantine, then reject — reading the aggregate reports at each step. For a domain you never send from, publish a null SPF and a reject DMARC on day one; there is nothing to break.
Evidence test: Query the DNS TXT records for every domain in your tenant. Every one should have SPF and DMARC, and the sending domains should have DKIM selectors that resolve.
Microsoft 365 for Accountancy, Domain 3: Devices and Endpoints
Practice staff work from home, from client premises and from trains in January. A Microsoft 365 for accountancy tenant cannot tell the difference between a managed laptop and a personal machine unless you make it able to.
Control 10: Enrol every device and apply a security baseline
Intune enrolment plus the Microsoft security baseline gives a Microsoft 365 for accountancy practice the answers a Cyber Essentials assessor asks for without an interview: what is the device, who has it, is the firewall on, is the disk encrypted, what is the patch level. Without enrolment, all of those answers are a spreadsheet somebody maintained until they got busy.
Evidence test: Intune admin centre, Devices, All devices. Compare the count with your headcount plus known spares. Every gap is either a device you do not manage or a person working on something you have never seen.
Control 11: Patch inside 14 days, and prove it
The Danzell question set for Cyber Essentials added questions requiring that updates rated critical or high are applied within 14 days, and treats failure as an automatic fail. That covers operating systems, browsers, Office applications and the third-party software a Microsoft 365 for accountancy practice cannot live without — the PDF editor, the tax software, the bookkeeping client.
Set update rings in Intune so the deadline is enforced rather than requested, and keep one report that shows compliance percentage over time. A practice running Microsoft 365 for accountancy work at scale will always have three or four stragglers; the report is what turns them into a task list instead of a surprise.
Evidence test: Intune, Reports, Windows updates. Show the compliance percentage for the last 14-day window. Anything under 100% needs a named device and a reason.
Control 12: Deal with unmanaged and personal devices explicitly
Every Microsoft 365 for accountancy tenant has them: the partner’s iPad, the subcontracted bookkeeper’s own laptop, the seasonal January help. The wrong answer is to leave them outside the Microsoft 365 for accountancy scope and pretend they do not exist. The workable answer is app protection policies — the client data stays inside the managed Outlook and Office apps, cannot be copied into a personal app, and can be wiped without touching the owner’s photographs.
Evidence test: Intune, Apps, App protection policies. Confirm a policy exists targeting personal devices and check the assigned user count is not zero.
| Control | Minimum licence | Evidence lives in |
|---|---|---|
| 1. MFA everywhere | Any Business plan | Entra, Users |
| 2. Conditional access baseline | Business Premium (Entra ID P1) | Entra, Conditional Access |
| 3. No legacy authentication | Any plan; P1 to enforce by policy | Entra sign-in logs |
| 4. Separate admin accounts | Any Business plan | Entra, Roles |
| 5. Shared mailboxes, sign-in blocked | Any Business plan | Microsoft 365 admin centre |
| 6 to 7. Anti-phishing, Safe Links | Business Premium (Defender for Office P1) | Defender portal |
| 8. Forwarding block and rule audit | Any plan; alerting needs Premium | Defender portal, Exchange |
| 9. SPF, DKIM, DMARC | Any plan, plus DNS access | Public DNS |
| 10 to 12. Device management | Business Premium (Intune Plan 1) | Intune admin centre |
| 13 to 16. Labels, retention, DLP | Business Premium; Purview Suite for more | Purview portal |
| 17 to 19. Audit, alerts, backup | Premium plus a backup product | Purview, Defender, backup console |
Microsoft 365 for Accountancy, Domain 4: Client Data and Retention
This is the domain where a Microsoft 365 for accountancy build diverges most sharply from a generic hardening guide, because a practice has statutory retention periods that nobody else has.
Control 13: Sensitivity labels that people will actually apply
Three sensitivity labels beat fifteen in any Microsoft 365 for accountancy tenant. Something like Internal, Client Confidential and Restricted covers a practice, where Restricted means encrypted and traceable — the payroll file, the AML pack, the due diligence report on an acquisition. Publish them to everybody, set a sensible default, and stop.
The reason to bother with Microsoft 365 for accountancy labels is not the encryption. It is that a labelled document keeps its protection when it leaves the tenant, which is exactly what happens when a client asks you to email the accounts to their bank.
Evidence test: Purview portal, Information protection, Labels. Confirm the label policy is published to all users and check the label usage report shows real activity rather than three test documents.
Control 14: Retention policies mapped to the actual statutory periods
This is the Microsoft 365 for accountancy control that catches practices out, because the periods are all different and none of them is “forever”. Anti-money laundering records are five years under regulation 40 of the Money Laundering Regulations 2017. Companies House identity check records, if you are an Authorised Corporate Service Provider, are seven years. Tax records follow the client’s own obligation. Everything else follows practice policy and your insurer’s view of the limitation period.
| Record type | Retention | Source of the duty | Where to enforce it |
|---|---|---|---|
| AML customer due diligence | 5 years from end of relationship | MLR 2017, regulation 40 | Purview retention label on the client site |
| Companies House identity checks | 7 years | ACSP obligations | Dedicated library with a 7-year label |
| Engagement and fee correspondence | Practice policy, commonly 6 years | Limitation period, PII insurer | Exchange retention policy |
| Leavers’ mailboxes | Defined period, then delete | UK GDPR storage limitation | Inactive mailbox plus retention policy |
| Teams chat and channel messages | Shortest defensible period | UK GDPR storage limitation | Purview retention policy for Teams |
Evidence test: Purview, Data lifecycle management. Print the policy list and show, for each row of the table above, which policy delivers it. A row with no policy is a compliance gap you have written down.
Control 15: Data loss prevention for the identifiers a practice handles
Out-of-the-box DLP templates are built around credit card numbers, which is not what a Microsoft 365 for accountancy tenant leaks. Tune the policies for the identifiers that matter here: National Insurance numbers, UTRs, sort codes and account numbers, passport numbers from AML packs. Start in the mode that warns the user rather than blocks, read the results for a month, then tighten.
The most valuable rule in a practice is usually the simplest: warn when a message containing bank details is being sent to a recipient outside the tenant, and require a justification.
Evidence test: Purview, Data loss prevention, Policies. Confirm at least one policy covering Exchange, SharePoint, OneDrive and Teams, and open the alerts view to show it has fired at least once.
Control 16: One structure per client, and an access review that runs
Client folders accumulate access. A junior helps on one file in 2023 and still has the whole client site three years later. Sensitivity labels do not fix that; access reviews do. Set one review per year across SharePoint sites and Teams, with the client relationship partner as reviewer, and make the default action removal rather than retention.
Evidence test: Entra, Identity Governance, Access reviews. Show one completed review with a date inside the last twelve months and a non-zero number of removals.
Microsoft 365 for Accountancy, Domain 5: Monitoring and Recovery
Control 17: Turn on audit logging and know how long it keeps
Unified audit logging is what turns “we think someone accessed the payroll mailbox” into a statement you can put in writing to a client or the ICO. Confirm it is on, confirm mailbox auditing is on for shared and privileged mailboxes specifically, and write down the retention period your licence gives you — because that number is your entire investigation window.
Evidence test: Purview, Audit. Run a search for the last seven days on any mailbox and confirm results return. Record the retention period alongside the screenshot.
Control 18: Alerts a small practice will actually read
An alert nobody reads is worse than no alert, because it creates a paper record of a warning that was ignored. Pick a short list and route it to a monitored destination: new inbox rule with external forwarding, sign-in from an unfamiliar country, elevation to a privileged role, mass file download from SharePoint or OneDrive, and any use of the break-glass account.
Evidence test: Defender and Purview alert policies. Show the enabled list and the recipient address, then confirm the address is a monitored shared mailbox rather than one person’s inbox.
Control 19: Backup that is separate from the tenant
Microsoft’s retention policies and its own backup product both help, but the recovery question a Microsoft 365 for accountancy practice must answer is broader: if the tenant is compromised or a mailbox is maliciously purged, what independent copy exists and how quickly can it be restored? Answer it in writing, with a tested restore, before January rather than during it.
Evidence test: Produce the date of the last successful test restore of a mailbox and a SharePoint document library, and the person who verified the contents.
Microsoft 365 for Accountancy, Domain 6: Governance and Ownership
Control 20: Named ownership, a review date, and one page of evidence
Every practice that gets this far loses its Microsoft 365 for accountancy baseline again within eighteen months unless someone owns it. Write down who owns the Microsoft 365 for accountancy configuration, when the review happens, and where the evidence for each of the twenty controls is stored. One page. Put the review in the practice diary for a quiet month — June works, January does not.
This is also the control that makes the other nineteen usable commercially. When a corporate client sends a supplier security questionnaire, or an insurer asks about cyber controls at renewal, the answer is a document rather than a week of scrambling.
Evidence test: The page exists, it names a person rather than a role that is vacant, and its review date is in the future.
The HMRC Agent MFA Rollout and Your Microsoft 365 for Accountancy Tenant
HMRC set out the timetable in Agent Update 141, published on 19 March 2026. It applies to web sign-in on GOV.UK for both the agent services account and HMRC online services for agents, and it runs on a separate track from anything in a Microsoft 365 for accountancy tenant, and it does not change how Making Tax Digital software or PAYE submissions authenticate.
The timetable, in the order it affects you
| Phase | Request by | MFA switched on |
|---|---|---|
| Voluntary, first window | 30 June 2026 | 15 July 2026 |
| Voluntary, second window | 31 July 2026 | 19 August 2026 |
| Mandatory, all remaining accounts | No action needed | 28 September to 15 October 2026 |
Codes arrive one of three ways: an authenticator app, which HMRC prefers and which works on a phone, tablet or computer; a text message from 60551; or an automated voice call from 01749 608007. The text and voice codes are six digits and expire after fifteen minutes.
The two decisions to make before activation day
The first is whether the Microsoft 365 for accountancy practice keeps a shared login or moves to individual staff logins. If you keep the shared login and choose an authenticator app, the seed key has to be distributed securely to every person who needs to sign in, so they all generate matching codes. That is a password-manager job, not an email job.
The second is administrators. Nobody can reset their own MFA, so every account needs at least two administrators before the switch is thrown. Practices that skip this discover the problem at the worst possible moment, because the first employee to sign in after activation is the one who gets asked how the firm wants to set MFA up.
Why this belongs in a Microsoft 365 for accountancy checklist at all
Because the tenant is where the attack lands. Nobody phishes an agent services account directly; they phish the mailbox of the person who can reset it, or they call the practice pretending to be HMRC and ask a stressed junior to read out a six-digit code in the last week of January. Controls 1, 5, 6 and 18 above are the ones that decide whether that call succeeds.
Train for it specifically. HMRC will never phone, email or text to tell somebody about a refund or ask them to claim one, and it publishes a reporting route — [email protected] for emails and 60599 for texts. Put both in the induction pack, alongside the practice’s own rule that no bank detail changes on the strength of an email alone.
What Microsoft 365 for Accountancy Does Not Cover
An honest Microsoft 365 for accountancy checklist names its own edges. Three significant risks sit outside the tenant entirely, and a practice that believes otherwise has a false sense of coverage.
Practice software sits outside Microsoft 365 for accountancy
IRIS, CCH, Sage, Xero, QuickBooks, Dext and the rest have their own identity models, their own MFA settings and their own audit logs. Some federate with Entra ID; many do not. Every one of them needs the same five identity questions asked separately, and the answers belong in the same Microsoft 365 for accountancy evidence pack.
The HMRC agent account and Companies House filings
Neither lives in your tenant. The agent services account is HMRC’s, and from November 2026 Companies House requires anyone filing on behalf of clients to be a registered Authorised Corporate Service Provider, supervised by a UK anti-money laundering supervisory body, keeping identity-check records for seven years and notifying Companies House within 14 days of any change — including the loss of that supervision. Those are practice governance obligations that no amount of tenant configuration satisfies.
The client’s own environment
Half of business email compromise against a Microsoft 365 for accountancy practice starts on the client’s side, not yours. The invoice really was sent from the client’s real mailbox, because the client’s mailbox was compromised first. The only defence that survives this is procedural: verified callbacks to a known number for any change of bank details, applied without exception, including when the request comes from someone senior in a hurry.
What Microsoft 365 for Accountancy Actually Costs
Prices below are UK list, excluding VAT, per user per month on an annual commitment, as published on the Microsoft UK storefront in August 2026. Practices buying through a partner usually pay less.
| Plan | UK list price | What it adds for a practice |
|---|---|---|
| Business Basic | £5.40 | Web apps and mail only; no conditional access |
| Apps for business | £9.80 | Desktop apps, no mailbox |
| Business Standard (with Copilot) | £18.10 | Desktop apps and mail; still no P1 |
| Business Premium (base) | £16.90 | Entra ID P1, Intune P1, Defender for Business, Defender for Office P1, Purview information protection |
| Business Premium (with Copilot) | £24.60 | The above plus Copilot |
| Defender Suite or Purview Suite add-on | £7.70 each, £11.50 for both | Deeper detection or deeper data governance |
Only one row on that table delivers the checklist
Business Premium is the Microsoft 365 for accountancy line where conditional access, device compliance, impersonation protection and information protection all arrive together. Everything below it leaves at least seven of the twenty controls unimplementable regardless of how carefully you configure the rest. That is not a Microsoft marketing point; it is the reason a Microsoft 365 for accountancy security discussion usually turns into a licensing discussion within ten minutes.
The worked example: a 34-person practice
Take the practice from earlier — 34 named staff, 11 shared or generic mailboxes, 4 administrator accounts, 49 identities in total. Shared mailboxes need no licence and admin accounts can be unlicensed cloud-only identities, so the bill is 34 seats.
At £16.90 that is £574.60 a month, or £6,895.20 a year. Spread across 34 people, that is £202.80 per person per year. If 25 of the 34 are fee earners, the security-bearing licence costs £275.81 per fee earner per year — the equivalent of roughly two chargeable hours at a typical practice rate.
What a Microsoft 365 for accountancy licence does not buy
A Microsoft 365 for accountancy licence does not buy configuration, and it does not buy attention. A Business Premium tenant with security defaults and nobody reading the alerts is a more expensive version of the same risk. Budget for the setup work and for someone to own control 20, or the licence spend is a line item rather than a control.
A 90-Day Plan for Microsoft 365 for Accountancy
Twenty Microsoft 365 for accountancy controls is too many to do at once and too few to spread over a year. Ninety days is the right shape, and the ordering below front-loads the controls that stop the attacks actually happening to practices.
Days 1 to 30: identity and the money channel
Controls 1, 2, 4, 5, 6 and 8, plus the DNS work in control 9. That is eight controls, and between them they close the credential-theft and payment-diversion paths. Do control 1 first and do it completely; a partial MFA rollout gives you the disruption without the protection.
Days 31 to 60: devices, mail hardening and legacy authentication
Controls 3, 7, 10, 11, 12 and 17 take the count to fifteen. This is the phase that needs an inventory: every device, every printer or application that sends mail, every third-party product with a login. Expect it to take longer than the configuration.
Days 61 to 90: data, retention, monitoring and ownership
Controls 13 to 16, 18, 19 and 20 finish the set at twenty. Retention is the item most likely to slip, because it needs a decision from the partners about how long things are kept rather than a setting from whoever administers the tenant. Get the decision in writing in month two so month three is configuration only.
Where to start with Microsoft 365 for accountancy if ninety days is short
If the practice can only do one thing this quarter, do control 1 across every account including the dormant ones. If it can do two, add control 8. Those two between them address the two failure patterns that produced both the DPP Law penalty and the majority of practice payment-diversion losses.
Turning Microsoft 365 for Accountancy Controls Into Evidence Clients Accept
A configured Microsoft 365 for accountancy tenant that nobody can prove is configured has no commercial value. Three audiences will ask, and they ask for different things.
Cyber Essentials and the Microsoft 365 for accountancy controls
Cyber Essentials is a self-assessment against five technical controls, verified by an assessor, and it is the cheapest external validation a practice can buy. The Danzell question set has been in force for applications since 26 April 2026, and existing certificate holders were given until 26 October 2026 to move across. Controls 1, 2, 3, 10, 11 and 12 of this Microsoft 365 for accountancy checklist map almost directly onto it.
Client procurement and due diligence questionnaires
Corporate clients increasingly send a supplier security questionnaire before renewing, and most of it is a Microsoft 365 for accountancy audit in disguise. The questions are predictable: MFA coverage, patching cadence, backup and restore testing, incident response, subprocessors, data location. Every one of those is answered by a control above. Keep the answers in one document and update it at the annual review rather than rewriting it per client.
Professional indemnity insurers
Cyber cover and PII renewals now ask specific technical questions, and an inaccurate answer is a coverage problem rather than an administrative one. Answer from the evidence tests, not from memory, and keep the screenshots with dates on them.
Common Mistakes in Microsoft 365 for Accountancy Deployments
| What practices do | Why it fails | What to do instead |
|---|---|---|
| Exclude two accounts from MFA “temporarily” | Automatic Cyber Essentials fail; the excluded account is the one that gets used | One documented break-glass account, alerted on |
| Leave conditional access in report-only | Produces logs, blocks nothing | Move to On after a fortnight of clean reporting |
| Use a licensed user account as a shared mailbox | Shared password, no accountability, costs a licence | Convert to a shared mailbox with sign-in blocked |
| Treat Microsoft retention as backup | Different job; a compromised tenant can lose both | Separate backup with a tested restore |
| Buy Business Premium and configure nothing | Pays for controls that are switched off | Budget the configuration alongside the licence |
| Send alerts to one person’s mailbox | Stops working the week they are on holiday | Monitored shared mailbox with a named deputy |
| Start the project in December | Collides with the Self Assessment peak | Start in spring or early summer |
The mistake underneath most of the others
Almost every failure above comes from treating cybersecurity as a project with an end date instead of a standing practice function, and Microsoft 365 for accountancy work is never finished. The tenant changes every month: Microsoft ships new defaults, staff join and leave, clients send new file types, and a setting that was correct in March quietly stops being correct by September. Control 20 exists precisely because the other nineteen decay.
Frequently Asked Questions About Microsoft 365 for Accountancy
Do we need Business Premium, or can we get there on Business Standard?
You cannot build Microsoft 365 for accountancy security on Standard. Conditional access, device compliance policies, impersonation protection and information protection all require the Entra ID P1, Intune P1, Defender and Purview components that only Business Premium carries. Standard leaves roughly seven of the twenty controls unavailable.
Does the HMRC agent MFA rollout replace MFA inside our tenant?
No. They are separate systems with separate credentials. HMRC’s rollout protects the agent services account and online services for agents; your tenant MFA protects the mailbox, files and devices that an attacker would use to reach that account in the first place. You need both.
How does this checklist relate to Cyber Essentials?
Six of the twenty controls map directly onto the Cyber Essentials technical controls, and several more support the evidence. Certification is not required to be secure, but it is the cheapest way to prove to a client that a Microsoft 365 for accountancy environment has been independently checked.
We are a two-person practice. Is this overkill?
No, and the breach survey says so: 42% of micro businesses reported a breach or attack. The Microsoft 365 for accountancy controls scale down cleanly — a two-person practice can complete controls 1, 4, 5, 8 and 9 in an afternoon. The difference is that the ninety-day plan becomes a ninety-day trickle rather than a project.
What about Copilot — does it change the security picture?
It changes what oversharing costs. Copilot surfaces whatever the signed-in user already has permission to see, so a client site with permissive access becomes a search result rather than a folder nobody opened. Control 16 is the prerequisite; do the access review before turning Copilot on, not after.
How long does the whole thing take in practice?
For a typical twenty to fifty person practice, expect three to five days of Microsoft 365 for accountancy configuration spread across the ninety days, plus the inventory time in phase two, which is the part that always runs long. The retention decision is the item most likely to hold up the finish, because it needs partner sign-off rather than admin access.
References
ATT: Multi-Factor Authentication — how can agents prepare?
HMRC: Scams warning as Self Assessment customers targeted
Treasury Committee: HMRC warned by Committee for handling of phishing attack
Companies House: Identity verification
GOV.UK: Being an Authorised Corporate Service Provider
GOV.UK: Verify your identity for Companies House
Money Laundering Regulations 2017, Regulation 40: Record keeping
GOV.UK: Money laundering supervision for accountancy service providers
Cyber Security Breaches Survey
ICO: Law firm fined £60,000 following cyber attack
ICO enforcement action: DPP Law Ltd
ICO: Enforcement action register
ICO: Report a personal data breach
NCSC: Cyber Essentials overview
NCSC: Small Organisations Guide to Cyber Security
NCSC: Phishing attacks — defending your organisation
ICAEW: Cyber security resources
Microsoft Learn: Set up multi-factor authentication
Microsoft Learn: Conditional Access overview
Microsoft Learn: Authentication strengths
Microsoft Learn: Passkeys and FIDO2 security keys
Microsoft Learn: Securing privileged access
Microsoft Learn: Deprecation of basic authentication in Exchange Online
Microsoft Learn: Anti-phishing policies
Microsoft Learn: Safe Attachments
Microsoft Learn: Configure DMARC
Microsoft Learn: Intune security baselines
Microsoft Learn: Sensitivity labels
Microsoft Learn: Retention policies and labels
Microsoft Learn: Data loss prevention
Microsoft Learn: Mailbox audit logging
Microsoft Learn: Access reviews