top of page

A Law Firm Lost Access to Their Files Overnight: Microsoft 365 Data Loss Explained

Apr 10
14 min read

Updated: Sep 1

A law firm lost access overnight – Microsoft 365 OneDrive, SharePoint and data management case study by SNL-Tech Services

Sometimes an IT problem that looks fairly simple at first exposes a much bigger issue underneath. I saw that firsthand with a small law firm I support when an employee left the firm and other employees suddenly lost access to files they had been using.


What initially appeared to be a file-access problem turned out to be an issue with how the firm's data had been stored and shared. This kind of Microsoft 365 data loss can happen when a business doesn't realize that important shared information is actually tied to an individual employee's account. In this case, the files everyone thought of as shared company files were actually tied to the former employee's OneDrive.


I was able to help with the immediate issue, but it raised a much larger question about the firm's Microsoft 365 environment: Where does the firm's business data actually live, who controls it, and what happens to that data when an employee leaves?

Those are questions I think small businesses need to answer before an employee departure, security incident or other unexpected event forces them to.


Update: I originally wrote this article after helping a small law firm that unexpectedly lost access to shared files when an employee left. Since then, I've continued working with the firm and have learned much more about how its Microsoft 365 environment is structured. I've updated this article to reflect Microsoft's current OneDrive lifecycle guidance and to share the broader Microsoft 365 issues the original incident uncovered, along with the remediation I've proposed to address them


OneDrive and SharePoint Don't Serve the Same Purpose

One of the things I see in smaller Microsoft 365 environments is OneDrive and SharePoint gradually being used almost interchangeably. Employees need to share something, they find a way that works, and over time those individual decisions can become part of the company's normal workflow.


I generally think about OneDrive as the user's work area. It makes sense for an individual's working files and documents, including files they may occasionally need to share with someone else. When information belongs to the business and needs to remain available to a group of people regardless of whether one particular employee stays or leaves, SharePoint is often the more appropriate home.


The issue at this law firm wasn't that OneDrive failed. Employees had simply come to depend on information stored in an individual's OneDrive as though it were a permanent shared location for the firm. That worked while the employee was there and everyone had access, but it became a very different situation when that employee left.

This is why I think it's important for businesses to make an intentional decision about where information belongs rather than allowing convenience to make that decision over time.


What Actually Happens to OneDrive When an Employee Leaves?

This is one area I specifically wanted to update from the original version of this article because Microsoft's handling of OneDrive accounts has changed and there isn't one universal timeline that applies every time an employee leaves.


If a Microsoft 365 user is deleted, Microsoft retains the user's OneDrive for the retention period configured by the organization. The default deleted-user OneDrive retention period is currently 30 days, although an administrator can configure a different retention period. After that retention period, the deleted user's OneDrive moves into the site collection recycle bin, where it is retained for another 93 days before permanent deletion unless another applicable retention mechanism preserves the data.


An unlicensed OneDrive account where the underlying user hasn't been deleted is handled differently. Microsoft's current lifecycle policies for unlicensed OneDrive accounts include read-only and archival stages based on how long the account has remained unlicensed. Retention policies, legal holds and other Microsoft 365 data-management settings can further affect what happens to the information.


For a business owner, the important takeaway isn't memorizing Microsoft's timelines. It's understanding that deleting a user, removing a license and preserving the former employee's business data are separate decisions. Employee offboarding needs to account for both the person and the company information that person leaves behind.


What This Microsoft 365 Data Loss Incident Revealed

As I continued working with the firm, it became clear that the OneDrive issue was part of a larger Microsoft 365 management problem. Like many small businesses, their technology had evolved over time rather than being designed around one consistent strategy for identity, devices, data and access.


The firm currently has a mixture of Windows configurations. Some computers use local Windows accounts, some have been set up with personal Microsoft accounts, and some devices are running Windows 11 Home rather than Windows 11 Pro. Their use of Microsoft 365, OneDrive and SharePoint has also evolved as employees needed different ways to work and share information.


Any one of those configurations can exist without causing an immediate problem, which is part of the reason environments like this develop in the first place. The difficulty comes later, when I need to manage security, permissions, employee changes and company data consistently across computers and accounts that weren't all set up the same way.

That's one of the larger issues I want to address through the remediation I've proposed.


Having Microsoft 365 Isn't the Same as Having a Managed Microsoft 365 Environment

This is something I see frequently with small businesses. Microsoft 365 gets introduced, users are created and employees begin working. Someone creates a SharePoint site because they need somewhere to put files. An employee shares a folder from OneDrive. A new computer gets set up with a personal Microsoft account, while another computer is configured with a local account.


None of this necessarily prevents employees from getting their work done. In fact, the fact that everything appears to work is often why these environments can remain this way for a long time.


The weaknesses tend to become visible when something changes. An employee leaves. An account is compromised. A computer needs to be replaced. The company wants to introduce a new technology such as Copilot. Someone needs access to information and nobody is quite sure where it lives or why one person can access it while another can't.

The problem isn't that the business chose Microsoft 365. The problem is that nobody ever designed how Microsoft 365 should work for the business.

That's the larger issue I want to address with this firm.


The Microsoft 365 Audit and Remediation I've Proposed

I've since offered the firm a Microsoft 365 Audit and remediation project to address the environment more comprehensively. The work hasn't been implemented yet. The firm is currently determining the right time to schedule it because some of the remediation will require me to have access to employee computers while I perform upgrades, rebuild and migrate profiles and standardize how the devices are configured.


As part of the project, I plan to upgrade the firm's Microsoft 365 licensing from Business Standard to Business Premium. The additional identity, device-management and security capabilities available with Business Premium will give me a stronger platform for implementing the controls I want in this environment.

The licensing change is only one part of the project. The real work is configuring those capabilities around the firm's users, computers, data and workflow and then continuing to manage them appropriately.


My proposed remediation goes well beyond fixing the original OneDrive problem. I want to create a more consistent Microsoft 365 environment where company identities, devices, permissions, data, retention, backup and security controls are intentionally managed instead of continuing to build on configurations that accumulated over time.


Standardizing the Computers and User Identities

Part of that work involves upgrading applicable computers from Windows 11 Home to Windows 11 Pro so I can use the business identity and management approach I've designed for the environment. I also plan to rebuild and migrate user profiles where necessary and move the firm away from the mixture of local Windows accounts and personal Microsoft accounts being used on company computers.

Combined with the move to Microsoft 365 Business Premium, this gives me a much better foundation for standardizing the environment around company-controlled identities and managed devices.


There is a practical reason for doing this beyond making the computers more consistent. I want a clear relationship between the employee, the identity the firm controls, the device that employee uses and the business resources that person is permitted to access. When those pieces are managed consistently, it becomes much easier for me to apply security policies, manage access and make changes when someone joins the firm, changes roles or leaves.


Rethinking How the Firm Uses OneDrive and SharePoint

The original incident also made it clear that I need to establish a better distinction between how the firm uses OneDrive and SharePoint. An employee's OneDrive shouldn't quietly become the permanent home for information that other employees depend on to run the business.


As part of the proposed remediation, I plan to revisit the firm's SharePoint sites and document libraries and look at how the data should be organized based on how the firm actually works. Simply moving more files into SharePoint wouldn't solve the underlying problem. I want the information organized in a way that makes sense for the business and can continue to be managed as the firm changes.


Permissions are a big part of that work. I want the appropriate security groups in place so access is controlled based on who actually needs the information rather than relying on years of individual sharing decisions. That should make access easier to manage when someone joins the firm, changes responsibilities or leaves because I'm managing access through an intentional structure rather than trying to remember every folder or document someone may have been given permission to use.

For a law firm dealing with client, case and internal business information, I think that distinction is especially important.


Retention Needs to Be Part of the Design

Retention is another part of the environment I plan to streamline. Instead of simply asking how long Microsoft keeps something, I want the firm to consider how long different types of information need to be retained and what policies should support those requirements.

Those decisions can affect email, SharePoint documents, OneDrive data and other information stored throughout Microsoft 365. They also need to fit the firm's actual business and legal requirements rather than being based solely on whatever Microsoft happens to do by default.


Retention also needs to be separated from the backup conversation. Microsoft 365 provides native capabilities such as retention, version history, recycle bins and recovery features, and Microsoft also offers Microsoft 365 Backup as a separate service. Those are all useful capabilities, but retention and backup address different parts of data protection and recovery.

For this firm, I want both to be intentional.


A Managed Microsoft 365 Backup Is Also Part of My Proposal

As part of the remediation proposal, SNL-Tech Services would provide the firm with a managed Microsoft 365 tenant backup solution designed to provide local and cloud-based backup protection for the Microsoft 365 data covered by the solution.

The service goes beyond installing backup software. I monitor client backups daily and provide a monthly backup report so the client has visibility into the status of the backup environment. I also perform quarterly tested restores and provide a report documenting the recovery test.


I include restore testing because a successful backup job doesn't necessarily tell me everything I want to know about recoverability. I want to periodically prove that protected information can actually be restored.

For this firm, that means having a recovery strategy for the applicable email, files and documents stored within the Microsoft 365 environment instead of waiting until an incident occurs to find out whether the backup strategy works the way everyone assumed it did.


Why Copilot Makes This Work More Important

There's another reason I believe the firm should address the environment before moving much further with Microsoft 365 Copilot: they have been considering introducing Copilot for their employees.


Before I recommend expanding AI use, I want to understand and secure the environment underneath it. That is the same approach I've been taking when I talk with other small businesses about AI adoption.

“Responsible AI adoption doesn't start with choosing an AI product. It starts with understanding the business, securing the environment underneath it and then deciding how AI fits into it.” — Shay, SNL-Tech Services

For this firm, that means understanding how employees authenticate, which devices are company controlled, where client information is stored, how SharePoint permissions are assigned, who has access to sensitive information and whether appropriate retention and backup strategies are in place.


Microsoft 365 Copilot works within the permissions a user already has in Microsoft 365. It doesn't independently correct an environment where a user already has access to information they shouldn't need. That makes the work I'm proposing around SharePoint structure, security groups and access especially important before the firm expands its use of Copilot.


AI isn't creating the permission problem. It can, however, make existing information much easier for an authorized user to discover and work with, which is one reason I want the underlying environment in better shape first.


Identifying and Protecting Sensitive Information

The proposed remediation also includes work around identifying and labeling sensitive information within Microsoft 365.


A law firm's Microsoft 365 environment can contain client information, case documents, financial information, internal business records and other sensitive data. I want the firm to have a sensible approach to identifying that information and determining what protections should apply to it.


Microsoft Purview sensitivity labels can be part of that approach. Copilot respects supported sensitivity labels, encryption and the Microsoft 365 access controls already applied to content, but I don't believe in enabling a feature simply because it's available.

The first question needs to be what the firm considers sensitive and how that information is actually used. From there, I can help implement the technical controls that support those decisions.


This becomes even more important if the firm moves forward with Copilot. Before giving employees another powerful way to discover and work with information across Microsoft 365, I want the identity, permissions and information protections underneath it to make sense.


Why I Start With a Microsoft 365 Audit

This firm's experience is a good example of why SNL-Tech Services offers a Microsoft 365 Audit.

Before I start changing an environment, I want to understand how the business is using Microsoft 365 today. Depending on the company, that can mean reviewing:

  • User identities and authentication

  • Administrative access

  • Microsoft 365 licensing

  • Company computers and how users sign into them

  • OneDrive usage

  • SharePoint sites, libraries and permissions

  • Security groups and access

  • Email and Microsoft 365 security settings

  • Retention policies

  • Microsoft 365 backup and recovery

  • Employee onboarding and offboarding

  • Sensitive information and data protection

  • Plans for technologies such as Microsoft 365 Copilot

Once I understand the environment, I can explain to the owner what I found, what concerns me and what I recommend changing. If the business wants to move forward, I can then perform the technical remediation needed to address those findings.

That's an important distinction in how I approach these projects. The audit tells us where the problems are. The remediation is the technical work required to fix them.


An Employee Leaving Shouldn't Put Company Data at Risk

The original problem that started this story was fairly straightforward: an employee left and other employees suddenly couldn't access files they needed. What we've learned from it is much broader than simply telling people not to put shared files in OneDrive.

A business needs to know where its information lives, who controls it and what should happen to it when an employee leaves. It also needs to distinguish between information that belongs in an employee's individual workspace and information that needs to remain available to the business.


That eventually leads into larger questions about SharePoint permissions, company-controlled identities, retention, backup, device management and security. For businesses considering AI, it also means making sure those things are understood before giving employees new ways to find and interact with company information.

The immediate missing-files problem was fixed. The larger Microsoft 365 environment is the next step, and the firm is currently working out when it can schedule the remediation so I can have the access to its computers necessary to complete the upgrades and profile migrations.


When that happens, my job will be to take what I've learned about the environment and turn it into something that is more consistent, easier to manage, better protected and better prepared for where the firm wants to go next.


Frequently Asked Questions

What happens to an employee's OneDrive when they leave a company?

It depends on what the administrator does with the Microsoft 365 account and what retention policies are configured. Deleting a user and removing a user's license aren't the same thing, and Microsoft uses different lifecycle processes depending on what happens to the account.

That's why I recommend having a defined Microsoft 365 offboarding process rather than relying on Microsoft's default behavior to determine what happens to important company information.


Should company files be stored in OneDrive or SharePoint?

It depends on how the information is being used. I generally view OneDrive as an individual's working area. Information that needs to remain available to a team, department or business regardless of whether one employee stays or leaves is often better suited to an appropriately structured SharePoint environment.

The important part is deciding intentionally where business information belongs.


Is Microsoft 365 retention the same as backup?

No. Microsoft 365 provides native retention, versioning, recycle-bin and recovery capabilities, and Microsoft also offers Microsoft 365 Backup as a separate service. Retention and backup solve related but different problems, and I believe both need to be considered as part of a business's data-protection and recovery strategy.


Why test Microsoft 365 backups if the backup reports say they're successful?

A successful backup job tells me the backup process completed. A tested restore gives me additional evidence that protected information can actually be recovered.

That's why the managed Microsoft 365 backup service I offer includes daily monitoring, monthly reporting and quarterly tested restores with a recovery report.


Why does Windows 11 Home matter in a business environment?

Windows 11 Home doesn't support Microsoft Entra join. Depending on the identity and device-management architecture I'm implementing, upgrading applicable business computers to Windows 11 Pro may therefore be necessary.

For this firm, those upgrades are part of the proposed standardization and remediation work.


Why upgrade from Microsoft 365 Business Standard to Business Premium?

Business Premium provides additional identity, device-management and security capabilities that I can use to build a more centrally managed environment.

For this firm, upgrading the licensing is part of the remediation plan. The license itself doesn't secure or manage the environment; the value comes from properly configuring and maintaining the capabilities it provides.


Does Microsoft 365 Copilot see everything in the company?

No. Microsoft 365 Copilot works within the permissions of the individual user and doesn't automatically give someone permission to information they couldn't otherwise access.

The concern is that a business may already have overly broad permissions or overshared information. That's why I want SharePoint permissions, security groups and data governance reviewed before the firm expands its use of Copilot.


Why are sensitivity labels important before deploying Copilot?

Sensitivity labels can help identify and protect sensitive Microsoft 365 information. They don't replace correctly configured permissions, but they can provide another layer in a broader information-protection strategy.

For a law firm considering Copilot, I want the business to understand what sensitive information exists and how it should be protected before introducing another powerful way for employees to discover and work with Microsoft 365 data.


What does an SNL-Tech Services Microsoft 365 Audit look for?

The exact scope depends on the business, but I can review identities, administrative access, authentication, licensing, security settings, devices, OneDrive, SharePoint, permissions, email security, retention, backup and other Microsoft 365 configurations that affect how the business protects and manages its information.

The audit provides the findings and recommendations. When a client wants to move forward, I can also perform the technical remediation and implementation necessary to address those findings.


The Bigger Lesson

What started with a law firm losing access to shared files has become a much larger conversation about how its Microsoft 365 environment works. I don't think that's unusual for a small business. Technology tends to grow over time as employees come and go, new computers are added, files are shared and new Microsoft services become available.

Eventually, a business can have an environment that works every day but isn't necessarily organized, secured or managed the way it would be if someone designed it intentionally today.


That's what I'm proposing to change for this firm. The remediation isn't about buying more technology for the sake of having more technology. It's about standardizing identity and devices, organizing business data appropriately, controlling access, establishing intentional retention, protecting Microsoft 365 data with tested backups, identifying sensitive information and creating a stronger foundation before introducing tools such as Copilot.


For me, all of those pieces are connected. Whether I'm working on Microsoft 365, cybersecurity, backup or AI, the technology needs to support how the business actually

operates.


Understand the business. Understand the environment. Secure what is underneath it. Then decide what technology belongs on top of it.


Additional Information & Resources

Microsoft — Delete a User from Your OrganizationMicrosoft's guidance covering user deletion and what happens to a former employee's OneDrive data.Microsoft guidance for deleting a Microsoft 365 user


Microsoft — Managing Unlicensed OneDrive AccountsMicrosoft's guidance covering the lifecycle of OneDrive accounts that no longer have a license.Microsoft guidance for unlicensed OneDrive accounts


Microsoft — Microsoft 365 BackupMicrosoft's documentation covering Microsoft 365 Backup and supported Microsoft 365 workloads.Microsoft 365 Backup overview


Microsoft — Microsoft Entra Joined DevicesMicrosoft's documentation covering Microsoft Entra join and supported Windows editions.Microsoft Entra joined devices


Microsoft — Microsoft 365 Copilot ArchitectureMicrosoft's documentation explaining how Copilot works with Microsoft 365 organizational data and existing permissions.Microsoft 365 Copilot architecture


Microsoft — Data Security and Compliance for Microsoft 365 CopilotMicrosoft's guidance covering permissions, information protection, sensitivity labels and data-security considerations surrounding Copilot.Microsoft 365 Copilot data protection guidance

Comments


bottom of page