What Case-Based Access Control Actually Means for Law Firms
Case-based access control is the security discipline of scoping access to matter files, correspondence, and client data to the specific attorneys and staff actually working that matter, instead of leaving access open across the whole firm. In most Miami law firms today, the honest answer to who can see a client’s file is everybody with a login. Case-based access control replaces that default with a permission model built around the matter itself. Only the responsible attorney, the assigned associates, the paralegal on the file, and the specific administrative support tied to that matter can open it. Everyone else on the firm’s Microsoft 365 tenant is walled out.
Why Firm-Wide Access Is the Default (and the Problem)
Practice management systems and document platforms ship with permissive defaults because permissive defaults are easier to deploy. The initial rollout throws every user into a single security group, every document library inherits open permissions from the site, and nobody comes back to tighten the model once the firm goes live. Five years later, an associate can pull a partner’s confidential merger file, a paralegal can read discovery on an unrelated matter, and a laid-off staff account still holds access nobody remembered to remove. This is the exposure case-based access control is designed to eliminate.
The Compliance Case for Case-Based Access Control
Case-based access control is no longer optional for firms that hold themselves out as compliance-mature. Cyber insurance carriers ask about it on renewal questionnaires. Corporate clients following SOC 2 or ISO 27001 ask about it in their vendor due-diligence packets. State bar ethical rules on protecting client confidences ask about it implicitly. And any firm that has been through a matter dispute knows the deposition question about who inside the firm had access to specific files. Case-based access control is the answer to all four conversations at once.
How Case-Based Access Control Works in Microsoft 365
Most Miami law firms run their document environment on Microsoft 365, which means case-based access control is built on Microsoft Entra ID groups, SharePoint site permissions, and sensitivity labels through Microsoft Purview. Each active matter gets a dedicated SharePoint site or document library, its own Entra ID security group scoped to the attorneys and staff working the matter, and a sensitivity label that enforces the permission at the document level even if the file leaves the site. Microsoft’s sensitivity label documentation covers the label engine, and Microsoft’s SharePoint permission guidance covers the underlying site model. Together they produce a permission architecture that is both auditable and enforceable.
Sensitive Matters and the Ethical Wall
Certain matters require more than scoped access, they require an ethical wall. A firm representing two parties in adverse proceedings, a matter with sealed pleadings, or a personnel investigation of a partner all need a hard barrier that no other attorney at the firm can cross. Case-based access control makes the ethical wall enforceable at the tenant level rather than relying on a policy sitting in the office manual. The wall is a technical control, not a promise, and it holds even when someone who should not have access goes looking for the file.
How the Rollout Actually Works
A structured case-based access control rollout for a mid-market law firm takes six to eight weeks. Week one is discovery: mapping the current document environment, identifying every open share, and inventorying active matters. Weeks two and three build the target permission model: matter-scoped Entra ID groups, SharePoint site templates, and the label taxonomy. Weeks four and five migrate the highest-sensitivity matters into the new model first, with the rest of the practice migrating on a rolling schedule. Weeks six through eight finish the migration, document the baseline, and hand the firm a governance model that keeps new matters scoped from day one. A strong managed cybersecurity posture depends on the governance holding after the project ends.
Common Mistakes to Avoid
Three mistakes trip up firms trying to roll out case-based access control without an experienced partner. First, over-scoping the initial migration and stalling on scale, the answer is a phased approach that migrates the highest-sensitivity matters first and lets the rest follow. Second, skipping the label layer, which leaves documents unprotected once they leave the site. Third, forgetting the offboarding process, which is where most access drift creeps back in. Any partner providing managed IT services for law firms today builds all three into the runbook from the start.
Case-Based Access Control: Frequently Asked Questions
Do we need Microsoft 365 E5 for case-based access control? No. Microsoft 365 Business Premium supports the core model. E5 adds richer auto-labeling and advanced classification, which are valuable for larger practices but not required to start.
How does case-based access control affect e-discovery? Positively. Scoped access means the discovery request is narrower, the collection is smaller, and the privilege log is cleaner.
Can partners still see everything? Only if the firm decides they should. Most firms scope partner access matter by matter as well, with a separate management group for firm-wide administrative visibility.
What about legacy matters? Legacy matters get migrated on a schedule. Highest-sensitivity first, everything else on a rolling basis over the following months.
Does case-based access control slow attorneys down? No, if the rollout is done well. Attorneys are added to matter groups when they are staffed and removed when they roll off. Everyday work is unaffected.
How VirtuWorks Runs Case-Based Access Control for Miami Law Firms
VirtuWorks has been running Microsoft 365 permission projects for Miami law firms since 1994 and has migrated dozens of South Florida practices to matter-scoped access. We hold ISO 27001, 20000, and 9001 certifications, SOC 2 Type II attestation, and operate a 24/7 US-based helpdesk with a 4-hour standard and 1-hour urgent SLA. Our local Miami IT support team runs case-based access control projects end-to-end for law firms across South Florida. Firms with an existing internal IT team engage under a co-managed IT arrangement so the rollout does not disrupt other operations. To scope a matter-scoped access project, Schedule a Call or reach us at 866-788-6599.