Case study
How a Melbourne Law Firm Eliminated Legacy Email Risk with Microsoft 365
A mid-sized Melbourne law firm needed to retire an ageing on-premises Exchange server and modernise its email, identity and endpoint controls without disrupting court deadlines or client confidentiality. Mycelium 365 delivered a staged migration to Microsoft 365, layered Defender protection, and brought identity into Entra ID with conditional access aligned to the firm's professional and Essential Eight obligations.
The challenge
The firm was running Exchange Server on hardware approaching end-of-life, with inconsistent mailbox backups, ad-hoc mobile device access and a flat permissions model that exposed privileged matter folders to too many staff. Several phishing incidents had bypassed the legacy gateway, prompting concerns ahead of an upcoming professional indemnity insurance review.
Partners also wanted greater confidence that client correspondence was retained, searchable for litigation hold, and protected against accidental deletion or insider mistake — without imposing friction on time-pressured legal staff.
The approach
Mycelium 365 ran a short discovery covering mailbox sizing, mobile estate, identity, retention requirements and Essential Eight maturity gaps. We sequenced the migration to move partners and litigation teams last, after support staff had validated the new environment.
Mailboxes and shared folders were migrated to Exchange Online with tenant-wide retention and litigation hold policies. Microsoft Defender for Office 365 replaced the legacy gateway, with Safe Links, Safe Attachments and impersonation protection tuned for the firm's most-targeted partners.
Identity was consolidated into Microsoft Entra ID with phishing-resistant MFA, conditional access by device compliance, and just-in-time access to privileged matter sites. Microsoft Intune brought firm-owned laptops and BYOD phones under a consistent compliance baseline.
Throughout, change communication and hands-on floor walks were prioritised so legal staff could keep billing time during cutover weekends.
The outcome
The firm decommissioned its on-premises Exchange server within twelve weeks, removing a major operational and security risk ahead of insurance renewal. Phishing reports from staff dropped sharply once Defender's impersonation and Safe Links protections were active.
Identity audits now produce evidence-ready reports for client security questionnaires, and the firm achieved practical alignment with Essential Eight Maturity Level One across application control, patching, MFA and admin privilege restriction — material the insurer accepted at renewal.
Partners gained confidence that client matter content is retained, recoverable and searchable, while staff report a faster, more reliable email and collaboration experience on any device.
Technologies used
- Exchange Online
- Microsoft Defender for Office 365
- Microsoft Entra ID (conditional access, MFA)
- Microsoft Intune (device compliance)
- SharePoint Online matter sites
- Microsoft Purview retention and litigation hold
Need a similar outcome?
Book a Discovery Call with Mycelium 365 to discuss your environment, security priorities, and the practical next step.
