Digitplus
Cybersecurity

Managed Devices for a Law Practice: Entra ID and Intune for a Small Nigerian Firm

How we moved a Nigerian law practice from personal laptops and shared passwords to a managed Microsoft Entra ID and Intune environment, and the friction that came with it.

Digitplus Editorial Team10 min readUpdated
An open filing cabinet drawer packed with paper client record cards

Ask most small Nigerian firms who owns their data and the honest answer is: nobody knows.

Client files live on personal laptops. Documents move over WhatsApp. Some staff use a company email address, some use a personal Gmail address they have had since university. Passwords are shared. When someone resigns, the offboarding process consists of hoping.

For a law firm, this is not untidy. It is a professional exposure.

An Abuja law practice we worked with was in roughly this position, not through negligence, but because it is the default state of every growing business that has never had a reason to solve it. A stolen laptop, one departing staff member with a grudge, or one convincing phishing email would each have produced a confidentiality breach that no amount of good lawyering could undo afterwards.

Here is what we built instead, and what it cost the firm in friction to get there.

Why a law firm specifically

Every business should manage its devices. A legal practice has to.

The obligation is layered. There is professional privilege, which is the client's, not the firm's. There are the Rules of Professional Conduct, which impose a confidentiality duty that does not soften just because the breach was technical rather than deliberate. And since 2023 there is the Nigeria Data Protection Act, which applies to any organisation processing personal data of Nigerians, which a law firm does on every single matter it touches.

None of these frameworks accept "the laptop was stolen and it wasn't encrypted" as an answer. Nor should they.

The practical translation: the firm needs to prove that client data is encrypted at rest, that access is controlled by identity rather than by who happens to be holding a device, and that access can be revoked completely and immediately. That is what Microsoft Entra ID and Intune do.

The stack: one SKU, not five products

We deployed Microsoft 365 Business Premium. This is a committed recommendation, not a survey of options.

For firms under 300 staff, which is the plan's hard ceiling, it is the single best-value security product available. One licence bundles Entra ID P1 for identity and conditional access, Intune Plan 1 for device management, Defender for Business for endpoint protection, Purview data loss prevention and information protection, and the whole Office, Exchange, SharePoint and Teams estate. Buying those capabilities separately costs multiples of the bundle.

Two buying traps, both live as at August 2026. The first is Business Standard, which small firms pick because it is cheaper and looks like it has Office in it. It does, and none of the security, which is the entire point. The second is newer: Microsoft's main pricing page now leads with a Copilot-bundled Business Premium at a materially higher price. If you do not want Copilot, make sure you are buying the plain SKU.

Identity first, and the mail nobody thinks about

Everything begins with identity, because in a modern environment identity is the perimeter. There is no office firewall protecting anything when half the staff are working from a laptop at home.

  • Named accounts for every individual. No shared logins, no generic "info@" that four people use. Every action in the tenant is attributable to a person. For a firm that may one day need to demonstrate who accessed what, this is foundational.
  • Multi-factor authentication enforced for everyone. Enforced through Conditional Access policy rather than left to individual choice. MFA alone eliminates the overwhelming majority of account compromise attempts.
  • Legacy authentication blocked. Old mail protocols that cannot enforce MFA are the most common way attackers walk around it. Blocked at the tenant.
  • A break-glass administrator account, excluded from conditional access, with credentials held securely offline. This exists so a misconfigured policy can never lock the firm out of its own tenant. It is the first thing a competent engineer sets up and the thing amateurs forget until the day it matters.
  • Self-service password reset, so a forgotten password on a Monday morning is a two-minute self-fix rather than a call to us.

Then the invisible work: we verified the firm's domain and configured SPF, DKIM and DMARC properly. Without it, anybody in the world can send email that appears to come from the firm's domain, to clients, to opposing counsel, to the court registry. Business email compromise in Nigeria frequently takes exactly this shape: a forged mail from a "partner" instructing a client to pay into a different account. Correct mail authentication makes that attack substantially harder to land.

Devices, and the policy that makes it real

Every firm-owned Windows device was enrolled into Intune. New devices are configured for Windows Autopilot, so a machine can be shipped sealed to a staff member and configure itself into the firm's environment on first boot with no engineer touching it. That depends on the device being registered to your tenant, which the supplier has to do at the point of sale, so confirm your reseller can before you order.

A device is only considered compliant if:

  • BitLocker disk encryption is enabled, with recovery keys escrowed automatically to Entra ID. This is the single control that turns a stolen laptop from a data breach into an insurance claim.
  • Defender antivirus is running and up to date.
  • The operating system meets a minimum patch level.
  • A password or PIN is set, with screen lock after a short idle period.
  • The firewall is on.

Then the control that makes all of it real. The core Conditional Access policy is simple to state and powerful in effect:

Access to firm data requires a managed, compliant device and a successfully authenticated user with MFA.

An unmanaged personal laptop cannot reach the firm's SharePoint. A stolen device marked non-compliant loses access. An attacker with a correct password but no second factor gets nothing. Everything else is refinement: sign-in risk policies, session controls, and geographic restrictions that make sense for a practice not operating outside Nigeria.

Applications follow the same logic. Office, PDF tooling, browsers and the practice's line-of-business software are deployed and updated through Intune. Nobody downloads an installer from a search result. Nobody runs a three-year-old PDF reader with known vulnerabilities because updating it was somebody else's job. This is ordinary managed services discipline applied to a twelve-person firm.

Files, phones, and the four-minute offboarding

We enabled OneDrive Known Folder Move, which redirects Desktop, Documents and Pictures into OneDrive automatically. Files stop existing solely on one laptop, so a device failure stops being a data loss event and becomes an inconvenience for one afternoon.

Matter files moved into structured SharePoint libraries, organised by client and matter, with permissions applied by group. Versioning is on, so an overwritten document is recoverable. The recycle bin retains deletions. A junior who deletes the wrong folder on a Friday is a five-minute fix on Monday.

For personal phones, App Protection Policies do the work without the firm managing anybody's handset. Firm data inside Outlook and Teams is containerised: it requires a PIN to open, it cannot be copied out into WhatsApp or a personal notes app, and it can be wiped remotely without touching a single personal photo. The staff member's phone remains their phone.

Which brings us to offboarding, the clearest demonstration of the project's value. Previously a departing staff member meant changing the shared password, hoping they kept no copies, and having no idea what was on their laptop. Now: disable the account, revoke active sessions, issue a remote wipe. Access to email, files, Teams and every connected application terminates within minutes.

One honest caveat on that last step. Account disable and session revocation take effect immediately, server-side. The device wipe only lands when the device next checks in. A laptop kept switched off or off the network stays un-wiped until it reconnects, which is exactly what a determined leaver would do. The encryption is what protects you in that window, not the wipe. This is true of every MDM platform, not a shortcoming of Intune, and it is worth understanding before you rely on the wipe as your control.

What it costs, and what it cost in friction

Microsoft 365 Business Premium lists at $22.00 per user per month on an annual commitment, as at August 2026. Confirm current pricing at the point of purchase, because Microsoft adjusts it and Nigerian billing has its own considerations.

For a small practice that is a genuinely modest operating cost. The comparison worth making is not against the cheaper licence tier. It is against the cost of one breach: the client relationship, the professional exposure, the regulatory position under the NDPA, and the reputational damage in a market where a law firm's entire product is trust.

The friction is the part these write-ups usually leave out, so here it is.

Personal laptops stop working. Conditional Access requiring a managed, compliant device is the whole point, and it means anyone who had been working off their own machine cannot any more. Either they get a firm device or they lose access. Budget for the hardware, and decide the policy before you switch the rule on rather than during the week it starts blocking people.

Someone will not want firm email on their phone. Once staff understand that the firm can wipe its own data from a personal handset, a proportion will decline, and they are entitled to. Have an answer ready: a work phone, or browser-only access with no local data. Telling people what the wipe does and does not touch, before enrolment rather than after, is what keeps this a conversation instead of an argument.

MFA needs a second factor everybody actually has. Enforcing it without exception means deciding in advance what happens for anyone without a suitable phone, and doing that in advance rather than granting exclusions under pressure, because an exclusion granted in a hurry tends to become permanent.

None of these are reasons not to do the work. They are the reasons it is worth planning the rollout as a change to how people work, rather than as a configuration exercise that happens to them.

This is not just for lawyers

Everything above applies, essentially unchanged, to any Nigerian business of roughly five to fifty people that handles information it cannot afford to leak. Accounting practices. Medical practices. Consultancies. Financial advisors. Recruitment firms. Any business with staff turnover and laptops. The wider cybersecurity essentials picture is the same argument at a lower level of detail.

The pattern is always the same, and the trigger is almost always the same too: somebody leaves badly, or a laptop goes missing, and the firm discovers in a single afternoon exactly how little control it had.

The work is much cheaper before that afternoon than after it.

Related to this: Managed Services.

Have a project that needs this thinking?

Tell us what you’re planning. We’ll come back with practical next steps and a clear, line-itemised proposal, no obligation.