August 24, 2026
Microsoft 365 provides healthcare practices with email, file storage, collaboration, and productivity tools, but simply having Microsoft 365 does not mean the environment is properly secured.
Healthcare practices should secure Microsoft 365 through multiple layers, including phishing-resistant authentication, Conditional Access, account protection, device management, email security, data protection, administrative controls, and ongoing monitoring. These safeguards work together to reduce the risk of compromised accounts, phishing attacks, unauthorized access, and exposure of electronic protected health information (ePHI).
Microsoft is also changing how organizations authenticate to Microsoft 365. Passkeys are becoming an increasingly important part of Microsoft's security strategy, while Microsoft-provided SMS and voice authentication are being retired. Healthcare practices should begin preparing for these changes now rather than waiting until older authentication methods are no longer available.
This eight-step framework provides healthcare practices with a practical approach for strengthening Microsoft 365 security.
Why Microsoft 365 Security Matters for Healthcare Practices
Microsoft 365 often contains or provides access to some of a healthcare practice's most sensitive business information.
Depending on how the practice uses the platform, that may include:
- Business email containing patient information
- Documents stored in SharePoint or OneDrive
- Files shared between employees
- Microsoft Teams conversations and files
- Administrative and financial information
- User identities and login credentials
A compromised Microsoft 365 account can potentially give an attacker access to much more than someone's email.
For example, a successful phishing attack could allow an attacker to impersonate an employee, access cloud files, send fraudulent messages from a legitimate account, or attempt to gain access to other systems.
That is why Microsoft 365 security should be treated as part of the practice's overall cybersecurity strategy rather than simply an email configuration project.
An 8-Step Microsoft 365 Security Framework for Healthcare Practices
Step 1: Move Toward Phishing-Resistant MFA and Passkeys
Passwords alone should never be the only protection between an attacker and your Microsoft 365 environment.
At a minimum, healthcare practices should require Multi-Factor Authentication (MFA) for appropriate Microsoft 365 accounts. However, organizations also need to recognize that not all MFA methods provide the same level of protection.
Traditional methods such as SMS text messages and voice calls can be vulnerable to phishing, social engineering, and other forms of account compromise. Microsoft is therefore moving organizations toward phishing-resistant authentication methods, with passkeys becoming the default authentication experience in Microsoft Entra ID.
Beginning September 1, 2026, users who are enabled for SMS or voice authentication will automatically be enabled for passkeys and prompted to register a passkey during MFA sign-in.
Beginning February 1, 2027, Microsoft will retire its own SMS and voice delivery for authentication. Organizations that still have a legitimate need for SMS or voice authentication will need to use a customer-managed telecommunications provider. Users whose only available MFA method is Microsoft-provided SMS or voice may otherwise be required to register a passkey before they can continue signing in.
Healthcare practices should begin preparing for this transition rather than waiting until the retirement date.
Phishing-resistant authentication options available within the Microsoft ecosystem include:
- Passkeys
- Passkeys in Microsoft Authenticator
- Windows Hello for Business
- FIDO2 security keys
- Other supported phishing-resistant authentication methods
Passkeys provide stronger protection because they rely on public-key cryptography rather than a password or verification code that a user can accidentally provide to an attacker.
Administrative accounts deserve particular attention because they may provide significantly greater access to the Microsoft 365 environment than standard employee accounts.
Healthcare practices should also consider maintaining appropriate backup authentication methods so employees are not unnecessarily locked out if a device or authentication credential is lost.
The long-term goal should be to move beyond simply asking:
"Do we have MFA?"
Instead, organizations should ask:
"Are we using phishing-resistant authentication that provides appropriate protection for our users, patient information, and Microsoft 365 environment?"
Step 2: Control How and Where Users Can Sign In
Strong authentication is an important security control, but healthcare practices can strengthen identity security further by controlling the circumstances under which users are allowed to access Microsoft 365.
Depending on the organization's Microsoft 365 licensing and security configuration, Conditional Access policies can evaluate factors such as:
- Who is attempting to sign in
- The device being used
- Whether the device meets security requirements
- The user's location
- The risk associated with the login
- The authentication method being used
For example, a normal login from a managed office computer may present significantly less risk than an unusual login attempt from an unfamiliar device or location.
Rather than treating every login exactly the same, Conditional Access allows organizations to apply additional protections based on risk.
Conditional Access can also play an important role as organizations transition toward phishing-resistant authentication by helping enforce stronger authentication requirements for appropriate users and situations.
This is also one reason Microsoft 365 licensing matters. Some security and management capabilities depend on the licenses assigned to users.
Step 3: Establish a Consistent User Access Process
Microsoft 365 security isn't only about stopping external attackers.
Healthcare practices also need a reliable process for controlling access as employees join the organization, change roles, and leave.
When a new employee starts, access should be based on what that individual actually needs to perform the job.
When an employee changes positions, permissions should be reviewed rather than simply adding new access on top of old access.
When someone leaves the organization, access should be removed promptly.
A consistent process should address:
- Microsoft 365 accounts
- Email access
- Shared mailboxes
- SharePoint and OneDrive permissions
- Microsoft Teams access
- Administrative privileges
- Connected applications
- Registered authentication methods
That final item becomes increasingly important as organizations adopt passkeys and other phishing-resistant authentication methods. When an employee leaves, organizations should make sure access credentials and registered authentication methods are handled as part of the offboarding process.
One common mistake is allowing permissions to accumulate over time.
An employee may begin in one position, move into another role, and eventually have access to information that is no longer necessary for the employee's current responsibilities.
Following the principle of least privilege means users receive the access necessary to perform their jobs without receiving unnecessary permissions.
Step 4: Secure the Devices Accessing Microsoft 365
Securing Microsoft 365 while ignoring the computers and mobile devices accessing it leaves a significant gap.
Healthcare employees may access Microsoft 365 through:
- Office workstations
- Laptops
- Smartphones
- Tablets
- Remote computers
Organizations should establish requirements for the devices permitted to access business information.
Depending on the practice and its Microsoft 365 licensing, device management may help enforce requirements such as:
- Device encryption
- Security updates
- Screen-lock policies
- Approved applications
- Device compliance
- Remote management
Microsoft Intune is one Microsoft technology that can help organizations centrally manage devices and apply security policies.
Device security also becomes increasingly connected to identity security as organizations adopt technologies such as Windows Hello for Business and passkeys.
The objective isn't simply to manage hardware. It is to make sure that a device accessing sensitive business information meets the practice's security requirements.
Step 5: Strengthen Email Security Against Phishing
Email remains one of the most common ways attackers attempt to compromise organizations.
Healthcare practices regularly receive messages from patients, insurance companies, laboratories, pharmacies, medical vendors, and other outside organizations. That makes it difficult for employees to simply avoid opening messages from unfamiliar senders.
Instead, practices need multiple layers of email protection.
Depending on the environment, these may include:
- Anti-phishing protection
- Spam and malware filtering
- Protection against malicious links
- Protection against malicious attachments
- Email authentication
- Impersonation protection
- Security awareness training
Technology alone cannot eliminate phishing.
Employees should also be trained to recognize suspicious requests, especially messages involving:
- Password resets
- Unexpected invoices
- Changes to payment instructions
- Urgent requests from executives
- Unexpected document-sharing notifications
- Requests for sensitive information
- Requests to approve unexpected authentication prompts
Moving toward phishing-resistant authentication can reduce the effectiveness of credential-stealing attacks, but it does not eliminate the need for email security and employee education.
A well-designed email security strategy combines technology, strong authentication, and employee awareness.
Step 6: Protect Sensitive Information and Control Sharing
Microsoft 365 makes collaboration easy, but convenience can create security problems when information is shared too broadly.
Healthcare practices should understand how employees use:
- OneDrive
- SharePoint
- Microsoft Teams
- Email attachments
- External sharing links
Permissions should be configured so employees can collaborate without unnecessarily exposing sensitive information.
Depending on licensing and organizational requirements, Microsoft 365 also provides capabilities that can help organizations classify, protect, retain, and control sensitive information.
Healthcare practices should pay particular attention to situations involving ePHI.
The important question isn't simply:
"Can our employees share this file?"
It should also be:
"Who should be able to access this information, how should it be shared, and what controls should protect it?"
Those decisions should align with the practice's security policies and HIPAA responsibilities.
Step 7: Limit and Protect Administrative Access
Administrative accounts can make significant changes to a Microsoft 365 environment.
If an administrator account is compromised, an attacker may potentially create accounts, change security settings, alter permissions, or interfere with other protections.
Healthcare practices should therefore tightly control administrative privileges.
Good practices include:
- Limiting the number of administrators
- Avoiding unnecessary administrative permissions
- Using separate administrative accounts where appropriate
- Protecting privileged accounts with phishing-resistant authentication
- Reviewing administrative access regularly
- Removing privileges that are no longer required
Employees should not receive administrative access simply because it is convenient.
The more powerful the account, the more carefully it should be protected.
As healthcare organizations plan their transition to passkeys and other phishing-resistant methods, privileged and administrative accounts should be among the highest priorities.
Step 8: Monitor, Review, and Improve Microsoft 365 Security
Microsoft 365 security should never be treated as a one-time configuration project.
Users change.
Devices change.
Microsoft introduces new capabilities.
Microsoft retires older technologies.
Attackers change their techniques.
The practice itself may add providers, locations, applications, or employees.
Healthcare organizations should regularly review areas such as:
- User accounts
- Administrative privileges
- Authentication methods
- MFA and passkey adoption
- Security alerts
- Suspicious sign-in activity
- Device compliance
- Email security
- External sharing
- Microsoft 365 licensing
- Security configuration
Microsoft's transition away from Microsoft-provided SMS and voice authentication is a good example of why ongoing review matters. A configuration that was acceptable several years ago may no longer represent current security best practices or may eventually stop being supported.
Significant organizational changes should also trigger additional reviews.
For example, opening another location, acquiring another practice, changing managed IT providers, or implementing a major new application may affect how Microsoft 365 should be secured.
The goal is continuous improvement rather than assuming that settings configured several years ago remain appropriate today.
Common Microsoft 365 Security Mistakes Healthcare Practices Should Avoid
Even organizations that have invested in Microsoft 365 can leave unnecessary security gaps.
Common mistakes include:
- Assuming Microsoft's default settings are sufficient for every organization
- Protecting some users with MFA while leaving others unprotected
- Assuming all MFA methods provide the same level of protection
- Continuing to rely on older authentication methods without a migration plan
- Allowing too many users to have administrative privileges
- Failing to disable former employee accounts promptly
- Allowing unmanaged devices to access business information without appropriate controls
- Sharing files too broadly
- Failing to review suspicious login activity
- Purchasing security capabilities without properly configuring them
- Assuming Microsoft 365 automatically makes the practice HIPAA compliant
The last point is particularly important.
Microsoft provides technologies that can support a healthcare organization's security and compliance efforts, but technology alone does not make an organization HIPAA compliant.
HIPAA compliance also involves administrative policies, procedures, physical safeguards, workforce responsibilities, risk management, and other organizational requirements.
Questions to Ask Your Managed IT Provider About Microsoft 365 Security
Healthcare practices shouldn't have to become Microsoft security experts themselves.
However, leadership should understand whether the organization's Microsoft 365 environment is being actively secured and managed.
Consider asking your managed IT provider:
What authentication methods are our employees currently using?
Don't simply ask whether MFA is enabled. Find out whether employees are using SMS, voice, authenticator applications, passkeys, Windows Hello for Business, security keys, or other methods.
What is our plan for Microsoft's transition to passkeys?
Organizations still relying on Microsoft-provided SMS or voice authentication should have a plan before the February 1, 2027 retirement date.
Are we using the security capabilities included with our Microsoft 365 licensing?
Purchasing a license doesn't mean every available security capability has been configured.
How do you monitor suspicious Microsoft 365 activity?
Ask what happens when unusual login behavior or other security events are detected.
How are new employees and departing employees handled?
There should be a consistent process for granting and removing access, including authentication credentials.
How are administrative accounts protected?
Administrative privileges should be limited and protected with stronger authentication.
Are employee devices managed?
Ask how the organization ensures that devices accessing Microsoft 365 meet appropriate security requirements.
How often is our Microsoft 365 security configuration reviewed?
Security settings shouldn't be configured once and forgotten.
Frequently Asked Questions
Is Microsoft 365 HIPAA compliant?
Microsoft offers services and security capabilities that can support healthcare organizations subject to HIPAA, but using Microsoft 365 does not automatically make a healthcare practice HIPAA compliant.
The practice remains responsible for properly configuring and using the technology as part of its broader compliance program.
Is Multi-Factor Authentication enough to secure Microsoft 365?
No.
MFA is an essential security control, but not all MFA methods provide the same level of protection. Microsoft is moving organizations toward phishing-resistant authentication methods such as passkeys because traditional methods including SMS and voice authentication provide weaker protection against phishing and account compromise.
Authentication should be combined with Conditional Access, device security, email protection, access management, administrative controls, data protection, and ongoing monitoring.
What is a passkey?
A passkey is a phishing-resistant authentication credential based on FIDO standards and public-key cryptography.
Unlike a password or one-time verification code, a passkey cannot simply be typed into a fraudulent website and handed to an attacker. The private credential remains protected by the user's device or credential provider, while the service uses a corresponding public key to verify the user's identity.
Passkeys can also work with device security features such as biometrics or a PIN, depending on the implementation.
Is Microsoft eliminating SMS and voice MFA?
Microsoft is retiring Microsoft-provided SMS and voice authentication delivery in Microsoft Entra ID on February 1, 2027.
Organizations that have a legitimate business, regulatory, or operational reason to continue using SMS or voice will have the option of using customer-managed telecommunications providers. However, Microsoft's recommended direction is to migrate users toward phishing-resistant authentication methods such as passkeys, Windows Hello for Business, or FIDO2 security keys.
Should healthcare practices wait until 2027 to move away from SMS authentication?
No.
Organizations should review their authentication environment and begin planning the transition before Microsoft's retirement deadline.
A phased approach gives healthcare practices time to test authentication methods, train employees, account for shared or specialized workflows, and address potential issues without waiting until a deadline creates unnecessary urgency.
Does Microsoft automatically secure everything in Microsoft 365?
No.
Microsoft secures the underlying cloud platform, but healthcare organizations remain responsible for many aspects of how their Microsoft 365 environment is configured and used.
User access, authentication methods, security policies, sharing permissions, device management, and other settings still require proper management.
Should every employee have the same Microsoft 365 security settings?
Not necessarily.
Security requirements may vary based on job responsibilities, administrative privileges, devices, applications, and access to sensitive information.
The objective should be consistent baseline protection with additional controls applied where risk requires them.
How often should a healthcare practice review Microsoft 365 security?
Microsoft 365 security should be monitored continuously, with more comprehensive reviews performed periodically and whenever significant changes occur.
Examples include adding a location, changing IT providers, implementing new applications, experiencing a security incident, significantly changing the workforce, or when Microsoft announces significant security or authentication changes.
Final Thoughts
Microsoft 365 can be an excellent platform for healthcare practices, but its security depends heavily on how the environment is licensed, configured, monitored, and managed.
An effective Microsoft 365 security strategy doesn't rely on one setting, one security product, or simply turning on MFA.
It combines phishing-resistant authentication, identity protection, device management, email security, data protection, administrative controls, and ongoing monitoring into multiple layers of defense.
Microsoft's move toward passkeys and away from Microsoft-provided SMS and voice authentication also demonstrates why healthcare practices need to continuously reevaluate their security environments. Security technologies and best practices evolve, and organizations need a strategy for evolving with them.
For healthcare practices, the objective is not simply to make Microsoft 365 harder to attack. It is to protect patient information, reduce operational risk, and provide employees with secure access to the technology they need to care for patients.
About ResTech Solutions
ResTech Solutions helps healthcare practices throughout the Houston area manage and secure Microsoft 365 as part of a broader proactive IT and cybersecurity strategy.
With more than 10 years of experience supporting healthcare practices, ResTech understands that effective technology support requires more than configuring software. We take the time to understand the people using the technology, how the practice operates, and the specific challenges employees encounter every day.
Our managed IT services include Microsoft 365 management along with the technology, security, monitoring, backup, and support services needed to maintain a reliable IT environment. Compliance-focused services, including Cyber Liability Management, can be incorporated separately based on the organization's needs.
If you're unsure whether your Microsoft 365 environment is properly secured or prepared for Microsoft's upcoming authentication changes, schedule a no-obligation discovery call with ResTech Solutions. We can discuss your current Microsoft 365 environment, review how your users authenticate today, and help you identify practical next steps for strengthening security and preparing for the transition to phishing-resistant authentication.

