Microsoft Entra ID vs. Local Accounts: What an IT Baseline Assessment Revealed at a Law Firm
- Shay

- May 30, 2025
- 16 min read
Updated: Aug 25

Updated August 2026: I originally wrote this article around one of the more visible problems I found at a small law firm: employees were using local Windows accounts, and the firm's approach to identities and file access needed work. Looking back at the project, that was only one part of a much larger story.
I have refreshed this article because what started as an IT Baseline Assessment ultimately turned into a substantial overhaul of the firm's technology environment, followed by a Microsoft 365 Security Review and Audit, implementation of the changes I identified, and detailed documentation of the resulting environment. The project included computers, identity, shared file storage, backup, Microsoft 365 security, Conditional Access, device compliance, network equipment, security monitoring, emergency access, and recovery documentation.
The bigger lesson is not that every small business needs the exact technology I implemented for this law firm. It is that an IT environment can appear to work every day while hiding problems the business owner has no reason to know are there.
“The environment was working when I arrived. That didn't mean it was properly managed. The Baseline Assessment showed us what was actually happening behind the scenes.”SNL-Tech Services
The Attorney Initially Called Me Because He Was Worried About His Backups
One of the attorney's biggest concerns when he first contacted me was backup. He believed the firm had a backup solution in place, but he wanted to make sure the information the practice depended on was actually protected.
That concern turned out to be justified.
As I worked through the IT Baseline Assessment, I discovered that the backup solution he believed was protecting the firm's data was not actually backing anything up. That finding became considerably more serious once I understood where the firm's shared files were stored.
Years of confidential client information and case files were sitting on a PC that was also being used by an employee as their everyday workstation. Other employees depended on that computer for access to shared company files.
The computer was working. Employees could access the files. There was a backup solution that the attorney believed was protecting those files. From the outside, there was not necessarily an obvious indication of how much depended on that one computer.
If that workstation had experienced a hard drive failure or another event that damaged the data before we corrected the environment, the firm was at risk of losing years of client and case information because the backup it thought it had was not actually protecting that data.
Fortunately, I found the problem before that happened.
That discovery is one of the reasons I put so much value on establishing an IT baseline. I do not want to assume something is protected because backup software is installed, or assume an environment is properly managed because everybody can get to their files.
I want to know what is actually happening.
What Is an IT Baseline Assessment?
An IT Baseline Assessment gives me a starting point. Before I start recommending products, replacing equipment, or changing Microsoft settings, I need to understand what the business already has and how people are actually using it.
For this law firm, that meant looking beyond individual computers. I needed to understand the firm's shared files, user accounts, backup, network, Microsoft 365 environment, security controls, licensing, and the other technology employees depended on every day.
The assessment itself did not magically fix those things. It identified the starting point and helped me determine what needed attention. Once I understood the environment, the project expanded into remediation, a deeper Microsoft 365 Security Review and Audit, implementation of the security changes, and documentation of the resulting environment.
That distinction matters because an assessment and an implementation are not the same service. The assessment answers, “Where are we today?” The implementation answers, “What are we going to change, and how are we going to get there?”
For this firm, there was quite a bit to change.
Their Shared Files Were Sitting on an Employee's Everyday Computer
One of the most important findings involved the firm's shared files.
A PC was being used as the central location for company files while an employee was also using that same computer as their everyday workstation. Other employees accessed the shared resources using shared credentials.
That arrangement worked in the most basic sense. Employees could open their files.
But I did not want years of company information dependent on an employee's daily workstation. That computer was being used for normal activities while simultaneously acting as the central location for data other employees depended on. A problem with that workstation could therefore affect considerably more than the employee sitting in front of it.
The shared credentials also limited accountability. If multiple people access company information using the same username, a log showing activity from that account does not necessarily tell me which person actually performed the action.
That is particularly important when a business wants to know who accessed, changed, moved, or deleted something.
I Moved the Shared Files to Dedicated Storage and Gave Users Individual Accounts
As part of the overhaul, I moved the firm's shared business files off the employee's workstation and onto dedicated network storage.
The employee could still have a computer for everyday work, but that computer no longer needed to serve two completely different purposes. The employee had a workstation, and the business had dedicated shared storage.
I also moved away from the shared username for file access. I created separate user accounts with individual passwords and configured access around those identities. I enabled logging so there was better visibility into activity associated with the individual accounts.
I also configured cloud backup for the firm's shared data.
This was more than a storage migration. I was separating an employee's workstation from the company's centralized data, improving individual accountability, adding logging, and establishing an actual backup path for information the business depended on.
That same concept of identifiable users and managed access carried into the Microsoft side of the project.
Microsoft Entra ID vs. Local Accounts: Why Did I Change the Computers?
Microsoft Entra ID vs. Local Accounts became an important part of this project as I reviewed how the firm's computers, identities, and Microsoft 365 environment were being managed.
As older PCs were replaced, I moved the new Windows computers into Microsoft Entra ID rather than continuing to build the environment around isolated local Windows accounts.
A local Windows account exists on the individual computer. A Microsoft Entra joined Windows device can instead allow the employee to sign in using the organization's Microsoft identity while giving me a better foundation for centralized device management and access controls.
That does not mean a local Windows account is automatically insecure, or that every small business must immediately replace every local account with Entra ID.
For this client, Entra ID was part of a larger management strategy. I wanted the firm's identities, Windows computers, Microsoft 365 environment, device policies, and access controls to work together instead of treating every PC as an isolated machine.
Does Microsoft Entra ID Actually Manage the Computer?
This is an important distinction.
Simply joining a Windows computer to Microsoft Entra ID does not mean every security setting on that computer is automatically managed.
For this law firm, Entra ID was one part of the design. I also configured the device management and compliance policies that allowed me to establish requirements for the firm's computers.
For a business owner, that distinction matters because Microsoft licensing is sometimes discussed as though owning the product means all of these controls are automatically configured.
It does not.
The licensing provides capabilities. Somebody still has to design, implement, test, document, and manage them appropriately for the business.
I discuss that distinction in more detail in Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?.
I Used Device Compliance and Conditional Access Together
Once I had the appropriate device management foundation in place, I configured device compliance policies and Conditional Access policies for the firm.
Device compliance gives me a way to evaluate whether a managed device meets the requirements established for that environment. Conditional Access can then use that information when determining whether a user should be allowed to access protected Microsoft resources.
For a business owner, the concept is easier than the terminology.
Knowing the username and password should not necessarily be the only thing that determines whether someone can access company information.
Depending on the environment, I may also want to know whether the device is one the business manages and whether it meets the security requirements we established for accessing protected resources.
That became part of the law firm's security model.
I Also Added Location Based Conditional Access Policies
I configured location based Conditional Access policies as another layer of access control.
For this client, I could use location information as one of the signals involved in determining where access should be allowed. I want to be careful about how I describe this because geographic restrictions are not a replacement for MFA, device compliance, identity protection, or the other security controls around an account.
I use location as one signal within a larger access strategy when it makes sense for the particular business.
This is another reason I do not recommend copying somebody else's Conditional Access policies from a blog post and turning them on without understanding the environment. A policy that makes sense for one small business could prevent legitimate employees from working at another.
Microsoft Defender Was Part of the Endpoint Strategy
I also configured Microsoft Defender protections on the firm's Windows computers.
Because employees worked with files stored on the network, I made sure files employees accessed through the network shares were included in the endpoint protection strategy. The protection was happening through the Windows endpoints as employees accessed and worked with those files. I am not saying Microsoft Defender was installed directly on the network storage device.
That distinction matters because I want business owners to understand what is actually protected rather than assume that installing one security product somehow covers every system in the environment automatically.
Security Alerts Need Somewhere to Go
I also configured Microsoft security alerting and created a dedicated mailbox for security notifications from the tenant. That is one of those pieces of IT management that a business owner may never see, but it matters.
I do not consider a security control fully implemented simply because I turned it on. I also want to know how I will learn that something needs attention.
If Microsoft generates a security notification and nobody responsible for the environment receives or reviews it, the business can have security technology without an effective monitoring process behind it.
“I don't consider a security control finished just because I turned it on. I also want to know who is watching it and what happens when it tells us something needs attention.”SNL-Tech Services
I Reviewed the Microsoft 365 Licensing Too
The firm's Microsoft licensing had changed over time, so the Microsoft 365 Security Review and Audit also included reviewing what licensing the business actually had and what made sense for the environment I was building.
I cleaned up the licensing rather than assuming the licenses that had accumulated over time still matched what the firm needed.
This is another area where small businesses can get into trouble. Microsoft licensing and Microsoft management are related, but they are not the same thing. Buying a license that includes a security capability does not mean that capability has been configured, tested, or monitored.
Likewise, cleaning up licensing should not be treated as simply finding the cheapest combination possible. I need to understand what capabilities the business is actually using before I start removing or changing licenses.
My Microsoft 365 Tenant Security Review goes deeper into what I look at when I review a tenant rather than simply checking which subscriptions appear on the bill.
I Created Emergency Access Accounts and Gave the Client Security Keys
Another part of the Microsoft overhaul involved emergency administrative access.
I configured emergency access accounts in the Microsoft tenant and protected those accounts using YubiKey security keys. I also provided the appropriate keys to the client.
The purpose is to maintain an alternative administrative path into the tenant if normal administrative access becomes unavailable. Those accounts need to be carefully protected, monitored, and tested because they exist specifically for situations where the normal access path is not working.
There is also a larger business ownership issue behind that configuration.
I may manage a client's Microsoft environment, but I do not believe that should mean the client has no appropriate way to regain administrative control of its own tenant without me. Emergency access needs to be protected appropriately, but the business should not be placed in a position where its IT provider is the only path back into an environment the client owns.
That same philosophy is why documentation became such an important part of this project.
The Network Needed Work Too
The Baseline Assessment was not limited to Microsoft 365.
I replaced network equipment, including the firewall and switch, and cleaned up and labeled the physical environment.
The labeling may sound insignificant compared with Conditional Access or Entra ID, but it serves a very practical purpose. If I am troubleshooting remotely and need someone onsite to reboot or reseat a particular piece of equipment, I do not want an employee standing in front of several devices trying to guess which one I mean.
If the equipment is clearly identified, I can give much more precise instructions.
That is part of making an environment supportable. I am not only thinking about how the equipment works on installation day. I am thinking about what happens six months later when something needs troubleshooting and I am not physically standing in front of it.
I also created a network diagram so there was documentation showing how the firm's environment was structured.
How Do You Know Your Business Backups Are Actually Working?
This project started with the attorney being concerned about backup, so I think this is one of the most important questions another business owner can take from the story.
Seeing backup software installed does not tell me the business's data is protected.
I want to know what is being backed up. I want to know whether the backup jobs are actually completing. I want failures to be visible. I want to understand how long recoverable data is retained. Most importantly, I want to understand how we would restore the information if the business actually needed it.
For this law firm, the original backup solution did not provide the protection the attorney believed he had.
As part of rebuilding the environment, I configured cloud backup for the firm's shared data. I also documented the recovery process so the firm had information explaining how its data could be restored from the cloud backup solution.
That last part matters.
Backup and recovery are related, but they are not the same thing.
A backup tells me another copy exists. Recovery planning asks what we are actually going to do with that copy when the business needs its information back.
Backup and Disaster Recovery are also part of my SNL-Tech Services Business IT Solutions because I look at recovery as part of the larger technology environment rather than as an isolated product.
I Documented the Environment I Built
Implementation was not the end of this project.
I created a Microsoft 365 runbook documenting the environment and the policies I implemented. I included screenshots of the actual policy configurations and maintained version history as the environment changed.
I also use an understandable naming convention for Microsoft policies. I do not want to come back to an environment months later and find a collection of policies with vague names that require me to open each one just to determine what it does. The name should give me a useful indication of the policy's purpose, and the supporting documentation should provide the deeper detail.
The documentation also included the network diagram and information about restoring the firm's data from backup.
I did not create that documentation just to produce a large document for the client. I wanted a runbook I could actually use to manage the environment and a record the client could retain showing how its technology had been configured.
This also creates a baseline for future changes. When I modify a policy or the network changes, I have somewhere to document what changed rather than relying on memory six months later.
“I don't want to just fix an environment. I want to understand the starting point, document what I change, and leave the business with an environment we can actually manage going forward.”SNL-Tech Services
Why Individual User Accounts Matter More Than Many Businesses Realize
One theme ran through several completely different parts of this project: individual accountability.
The original shared file setup used shared credentials. The Windows computers relied on local accounts. Microsoft 365 had its own identities. These pieces existed, but they were not being managed as one coherent environment.
I wanted identifiable users where appropriate, individual access, better logging, managed business devices, and policies that could make access decisions based on more than whether somebody knew a password.
That does not mean every small business needs the exact same architecture I implemented here.
It means I want to be able to answer basic questions when something happens.
Who accessed the information? Which device did they use? Was that device managed? Did it meet the company's requirements? Where did the sign in originate? What did the security tools report? Do we have logs? Do we have a backup? Can we restore the data?
Those questions become much harder to answer when everybody shares accounts, devices are unmanaged, logging is limited, and nobody has documented how the environment works.
Does Every Small Business Need Microsoft Entra ID and Intune?
Not necessarily in exactly the same way.
Technology should follow the business requirements rather than the other way around.
For a small business already relying heavily on Microsoft 365, especially one with company owned Windows computers, remote workers, sensitive business information, cyber insurance requirements, contractual security requirements, or a need for stronger device based access controls, Entra ID and Intune can provide a strong foundation for centralized identity and device management.
But I would not recommend that a business start turning on policies simply because it read that Conditional Access is good security.
The environment has to be understood first.
That is exactly why this law firm's project started with a baseline.
What Should a Small Business IT Baseline Assessment Look At?
The scope depends on the business, but this law firm demonstrates why I do not want to look at only one technology.
Depending on the environment, I may need to understand areas such as:
Computers and operating systems
User accounts and administrative access
Microsoft 365 licensing and tenant configuration
Entra ID and device identity
Device management and compliance
Conditional Access and authentication
Endpoint security
Shared file storage and permissions
Backup and recovery
Network equipment and configuration
Security logging and alerting
Documentation and ownership
Employee onboarding and offboarding
Emergency administrative access
The purpose is not to manufacture a list of things to sell the business.
The purpose is to establish what is actually there.
Sometimes the assessment confirms that something is already configured appropriately. Sometimes it identifies a small number of changes. And sometimes, as happened with this law firm, the baseline reveals that several interconnected parts of the environment need attention.
The Biggest Lesson From This Law Firm's IT Overhaul
When I first became involved, the firm's technology was working.
Employees could use their computers. They could open shared files. The network operated. Microsoft 365 worked. The attorney even believed the firm's data was being backed up.
The Baseline Assessment showed a different picture underneath that everyday functionality.
The backup the attorney believed was protecting years of confidential client and case information was not actually backing anything up. Critical shared data lived on an employee's everyday workstation. Employees accessed shared files through common credentials. Older computers needed replacement. The Microsoft environment needed a deeper security and licensing review. Devices needed a better management structure. The network needed work. Monitoring needed to be established. Emergency access needed to be planned. The resulting environment needed to be documented.
I did not fix all of that by installing one product.
I established the baseline, performed the Microsoft 365 Security Review and Audit, prioritized what needed to change, implemented those changes, and documented what I built.
The end result was an environment I could manage much more effectively going forward and one the client had documentation for rather than an assortment of technology nobody fully understood.
That is why I think an IT Baseline Assessment can be so valuable for a small business, particularly when the owner has inherited technology over many years or is not entirely sure what a previous IT provider configured.
You do not necessarily need to start by replacing everything.
You need to start by knowing what you actually have.
If your business is using Microsoft 365, shared files, company computers, backup, and network equipment but you are not sure how those pieces are configured or whether they are being actively managed, SNL-Tech Services Business IT Solutions can help establish that starting point.
Frequently Asked Questions
What Is the Difference Between a Local Windows Account and Microsoft Entra ID?
A local Windows account exists on an individual computer. A Microsoft Entra joined device allows an employee to sign into a supported Windows computer using the organization's Microsoft identity and provides a foundation for centralized cloud based device management and access controls. Entra join by itself does not automatically configure every security or management control on the computer.
Should a Small Business Use Local Accounts or Microsoft Entra ID?
It depends on the environment. For businesses heavily using Microsoft 365 and wanting centralized identity, cloud based device management, device compliance, or Conditional Access, Entra joined devices can provide a useful foundation. A local account is not automatically insecure simply because it is local. The decision should be based on how the business needs to manage identities, devices, applications, and access.
Does Joining a Computer to Entra ID Automatically Make It Secure?
No. Entra join establishes the device's identity relationship with the organization. Device management, compliance requirements, endpoint security, Conditional Access, user privileges, and other security controls still need to be appropriately configured.
Can Conditional Access Block Microsoft 365 Access From Unmanaged Computers?
Conditional Access can require a managed device to meet defined compliance requirements before access to targeted resources is granted when the underlying device management and compliance configuration is in place. The specific policies need to be designed and tested around the organization's requirements.
Can Microsoft 365 Block Sign Ins From Other Countries?
Microsoft Entra Conditional Access supports location conditions that can be used as part of access policies. I treat geographic restrictions as one signal within a broader security strategy rather than a replacement for MFA, device compliance, and other identity protections.
Why Are Shared User Accounts a Security Problem?
Shared accounts make individual accountability more difficult. If several employees use the same credentials, activity recorded under that account may not clearly identify which person performed the action. Individual accounts, appropriate permissions, and logging provide a better foundation for investigating access and managing employee changes.
How Do I Know Whether My Business Backup Is Actually Working?
Do not rely only on the fact that backup software is installed. Determine what data is actually included, whether backup jobs are completing, whether failures are monitored, how long data is retained, and how the information would be restored. For the law firm in this article, the Baseline Assessment revealed that the backup solution the attorney believed was protecting the firm's data was not actually backing anything up.
What Is a Microsoft 365 Emergency Access Account?
An emergency access account provides an alternative administrative path into a Microsoft tenant if normal administrative access becomes unavailable. These accounts need to be carefully protected, monitored, and periodically validated so they are available if the business actually needs them.
What Is an IT Baseline Assessment?
An IT Baseline Assessment establishes the current state of a business's technology environment. The specific scope depends on the organization, but it can include computers, identities, Microsoft 365, network infrastructure, shared files, security controls, backup, recovery, logging, and documentation. The purpose is to understand the starting point before deciding what changes are appropriate.
Is an IT Baseline Assessment the Same as a Microsoft 365 Security Review?
Not necessarily. In this client's project, the IT Baseline Assessment looked at the broader technology environment. The findings led into a deeper Microsoft 365 Security Review and Audit focused on the Microsoft tenant, licensing, identities, devices, policies, and security configuration. I then implemented and documented the changes identified through that work.
ADDITIONAL RESOURCES
Microsoft Learn: Plan Your Microsoft Entra Join Deployment
Microsoft guidance covering Entra joined Windows devices, device management, and Conditional Access considerations.Plan a Microsoft Entra Join Deployment
Microsoft Learn: Microsoft Entra Joined Devices
Microsoft's explanation of Entra joined devices, organizational sign in, cloud management, and access capabilities.What Is a Microsoft Entra Joined Device?
Microsoft Learn: Require Device Compliance with Conditional Access
Microsoft guidance explaining how device compliance information and Entra Conditional Access can work together.Require Device Compliance with Conditional Access
Microsoft Learn: Conditional Access Network and Location Signals
Microsoft documentation explaining named locations, IP ranges, countries and regions, and how location information can be used with Conditional Access.Conditional Access Network Signals
Microsoft Learn: Manage Emergency Access Accounts
Microsoft recommendations for emergency administrative access, including cloud only accounts, phishing resistant authentication, monitoring, and regular validation.Manage Emergency Access Accounts in Microsoft Entra ID
Microsoft Learn: Configure Microsoft Defender Antivirus Scanning
Microsoft documentation covering Defender Antivirus scanning options, including network files and mapped drives.Configure Microsoft Defender Antivirus Scanning
Microsoft Learn: Microsoft Intune Endpoint Security
Microsoft's overview of endpoint security, device policies, security baselines, Defender integration, and managed endpoint security.Endpoint Security in Microsoft Intune
.




Comments