Ask most small Nigerian firms who owns their data and the honest answer is: nobody knows.
Client files live on personal laptops. Documents move over WhatsApp. Some staff use a company email address, some use a personal Gmail address they have had since university. Passwords are shared. When someone resigns, the offboarding process consists of hoping.
For a law firm, this is not untidy. It is a professional exposure.
An Abuja law practice we worked with was in roughly this position — not through negligence, but because it is the default state of every growing business that has never had a reason to solve it. A stolen laptop, one departing staff member with a grudge, or one convincing phishing email would each have produced a confidentiality breach that no amount of good lawyering could undo afterwards.
Here is what we built instead.
Why a law firm specifically
Every business should manage its devices. A legal practice has to.
The obligation is layered. There is professional privilege, which is the client's, not the firm's. There are the Rules of Professional Conduct, which impose a confidentiality duty that does not soften just because the breach was technical rather than deliberate. And since 2023 there is the Nigeria Data Protection Act, which applies to any organisation processing personal data of Nigerians — which a law firm does on every single matter it touches.
None of these frameworks accept "the laptop was stolen and it wasn't encrypted" as an answer. Nor should they.
The practical translation: the firm needs to be able to prove that client data is encrypted at rest, that access is controlled by identity rather than by who happens to be holding a device, and that access can be revoked completely and immediately.
That is exactly what Microsoft Entra ID and Intune do.
The stack: one SKU, not five products
We deployed Microsoft 365 Business Premium. This is a committed recommendation, not a survey of options.
Business Premium is, for firms under 300 staff, the single best-value security product available anywhere. In one licence it bundles Entra ID P1 for identity and conditional access, Intune for device management, Defender for Business for endpoint protection, Purview for information protection, and the entire Office and Exchange and SharePoint and Teams estate.
Buying those capabilities separately costs multiples of the bundle price. The mistake small firms make is buying Business Standard because it is cheaper and looks like it has Office in it — which it does, and none of the security, which is the entire point.
What we actually built
1. Identity first
Everything begins with identity, because in a modern environment identity is the perimeter. There is no office firewall protecting anything when half the staff are working from a laptop at home.
- Named accounts for every individual. No shared logins, no generic "info@" that four people use. Every action in the tenant is attributable to a person. For a firm that may one day need to demonstrate who accessed what, this is foundational.
- Multi-factor authentication enforced for everyone, without exception. Enforced through Conditional Access policy rather than left to individual choice. MFA alone eliminates the overwhelming majority of account compromise attempts.
- Legacy authentication blocked. Old mail protocols that cannot enforce MFA are the most common way attackers walk around it. Blocked at the tenant.
- A break-glass administrator account, excluded from conditional access, with credentials held securely offline. This exists so that a misconfigured policy can never lock the firm out of its own tenant. It is the first thing a competent engineer sets up and the thing amateurs forget until the day it matters.
- Self-service password reset, so a forgotten password on a Monday morning is a two-minute self-fix, not a call to us.
2. Domain and mail hygiene
We verified the firm's domain and configured SPF, DKIM and DMARC properly.
This is invisible work with disproportionate impact. Without it, anybody in the world can send email that appears to come from the firm's domain — to clients, to opposing counsel, to the court registry. Business email compromise in Nigeria frequently takes exactly this shape: a forged mail from a "partner" instructing a client to pay into a different account. Correct mail authentication makes that attack substantially harder to land.
3. Device enrolment and compliance
Every firm-owned Windows device was enrolled into Intune. New devices are configured for Windows Autopilot, which means a machine can be shipped sealed to a staff member, and it configures itself into the firm's environment on first boot with no engineer touching it.
Then we set compliance policies. A device is only considered compliant if:
- BitLocker disk encryption is enabled, with recovery keys escrowed automatically to Entra ID. This is the single control that turns a stolen laptop from a data breach into an insurance claim.
- Defender antivirus is running and up to date.
- The operating system meets a minimum patch level.
- A password or PIN is set, with screen lock after a short idle period.
- The firewall is on.
4. Conditional Access: the actual control
This is where it all becomes real. The core policy is simple to state and powerful in effect:
Access to firm data requires a managed, compliant device and a successfully authenticated user with MFA.
An unmanaged personal laptop cannot reach the firm's SharePoint. A stolen device that has been marked non-compliant loses access. An attacker with a correct password but no second factor gets nothing.
Everything else is refinement — sign-in risk policies, session controls, geographic restrictions where they make sense for a practice that does not operate outside Nigeria.
5. Applications, deployed centrally
Office, PDF tooling, browsers and the practice's line-of-business software are all deployed and updated through Intune. Nobody downloads an installer from a search result. Nobody is running a three-year-old PDF reader with known vulnerabilities because updating it was somebody else's job.
6. Getting files off laptops and into the tenant
We enabled OneDrive Known Folder Move, which redirects Desktop, Documents and Pictures into OneDrive automatically and silently.
The effect is that files stop existing solely on one laptop. A device failure stops being a data loss event. It becomes an inconvenience for one afternoon.
Matter files moved into structured SharePoint libraries, organised by client and matter, with permissions applied by group. Versioning is on, so an overwritten document is recoverable. The recycle bin retains deletions. A junior who deletes the wrong folder on a Friday is a five-minute fix on Monday.
7. Personal phones, without managing personal phones
Staff want firm email on their own phones. The firm does not want to manage — or be responsible for — anybody's personal device.
App Protection Policies resolve this cleanly. The firm's data inside Outlook and Teams on a personal phone is containerised: it requires a PIN to open, it cannot be copied out into WhatsApp or a personal notes app, and it can be wiped remotely without touching a single personal photo.
The staff member's phone remains their phone. The firm's data remains the firm's data. This distinction, explained clearly during rollout, is what makes staff cooperate rather than resist.
8. Offboarding that takes four minutes
The clearest demonstration of the whole project's value.
Previously, a departing staff member meant: change the shared password, hope they did not keep copies, and have no idea what was on their laptop.
Now: disable the account, revoke all active sessions, and issue a remote wipe to the device. Access to email, files, Teams and every connected application terminates in minutes. The device, wherever it is, becomes an inert piece of aluminium.
For a practice holding privileged client material, that capability is worth the entire cost of the project on its own.
What it costs
Microsoft 365 Business Premium runs in the region of twenty-odd US dollars per user per month on an annual commitment. Confirm current pricing at the point of purchase — Microsoft adjusts it, and Nigerian billing has its own considerations.
For a small practice, that is a genuinely modest operating cost. The comparison worth making is not against the cheaper licence tier. It is against the cost of one breach: the client relationship, the professional exposure, the regulatory position under the NDPA, and the reputational damage in a market where a law firm's entire product is trust.
This is not just for lawyers
Everything above applies, essentially unchanged, to any Nigerian business of roughly five to fifty people that handles information it cannot afford to leak. Accounting practices. Medical practices. Consultancies. Financial advisors. Recruitment firms. Any business with staff turnover and laptops.
The pattern is always the same, and the trigger is almost always the same too: somebody leaves badly, or a laptop goes missing, and the firm discovers in a single afternoon exactly how little control it had.
The work is much cheaper before that afternoon than after it.



