top of page

Microsoft 365 SEC Compliance Guide for Investment Advisers

  • Aug 31
  • 10 min read

Microsoft 365 SEC Compliance Guide for Investment Advisers

Microsoft 365 SEC Compliance Guide for Investment Advisers

Microsoft 365 can hold almost every record an advisory firm creates, but that does not mean it preserves those records the way regulators expect.


Exchange Online may keep your email moving. SharePoint and OneDrive may make file access easier. Teams may help staff communicate faster. Still, the default setup is built for productivity, not SEC or FINRA recordkeeping. Users can delete messages. Files can sit in personal OneDrive folders. Teams chats may expire under the wrong policy. External sharing can spread client data beyond the people who need it.


The good news is that Microsoft 365 has the tools to support a compliant records program. The bad news is that someone has to configure them with the rules in mind.


This guide explains what the rules generally require and how registered investment advisers can configure Microsoft 365 to better support SEC and FINRA compliance obligations. This is informational only and is not legal advice. Work with compliance counsel or a qualified consultant before relying on any configuration as part of your formal compliance program.


Wide-angle view of a locked records vault with labeled archive boxes on metal shelves
Compliance starts with knowing what must be preserved and where it lives.

Microsoft 365 is not compliant by default


A default Microsoft 365 tenant is flexible by design. That flexibility creates risk for an advisory firm.


Common problems include:


  • Users can delete email, chats, and files before retention policies apply.

  • Shared mailboxes and former employee accounts are missed.

  • Teams conversations are treated as casual chat, even when they contain business records.

  • Marketing files are stored without review history or final approved versions.

  • SharePoint sites grow with no records taxonomy.

  • External sharing is wider than the firm realizes.

  • Audit logs are not retained long enough for an examination or investigation.

  • Backups are confused with retention, or retention is confused with backup.


That last issue matters. Retention policies preserve records for compliance. Backup protects against loss, corruption, ransomware, or tenant-level failure. A strong program usually needs both.


Microsoft 365 can help, but only when retention, access controls, supervision, audit, eDiscovery, and backup all work together.


The rules require complete, searchable, protected records


For an SEC-registered investment adviser, the anchor is Rule 204-2 under the Investment Advisers Act, often called the Books and Records Rule.


For practical Microsoft 365 planning, three parts matter most.


Business communications must be retained


Rule 204-2(a)(7) requires advisers to keep originals of written communications sent and received relating to the advisory business. In a modern firm, that can include:


  • Email in Exchange Online

  • Attachments sent through Outlook

  • Teams chats and channel messages

  • Shared files linked in messages

  • Client-related notes and correspondence

  • Internal communications about advice, recommendations, orders, performance, or client issues


Rule 204-2(a)(11) also requires copies of advertisements and marketing materials. Since the Marketing Rule reshaped how advisers think about testimonials, endorsements, performance advertising, and related disclosures, marketing records deserve their own retention and approval process.


Records must be kept long enough and be easy to produce


Most required adviser records must be kept for five years from the end of the fiscal year in which the last entry was made. The first two years must be in an easily accessible place.


In plain English, the firm should be able to locate and produce a complete, unaltered record set during an SEC examination without scrambling through user mailboxes, old laptops, and chat exports.


Electronic records must be indexed, protected, and backed up


Rule 204-2(g) addresses electronic records. It requires records to be arranged and indexed so they can be located, safeguarded from loss, alteration, or destruction, limited to authorized access, and separately backed up.


That maps directly to Microsoft 365 configuration:


Regulatory need

Microsoft 365 control that can support it

Keep written communications

Retention policies for Exchange, Teams, SharePoint, OneDrive, and Microsoft 365 Groups

Prevent premature deletion

Preservation through Microsoft Purview retention and, where appropriate, Preservation Lock

Locate records quickly

Microsoft Purview eDiscovery, indexing, labels, and consistent site structure

Limit access

Entra ID, Conditional Access, role-based permissions, sensitivity labels, and external sharing controls

Track activity

Microsoft Purview Audit and alerting

Review communications

Communication Compliance and supervisory review workflows

Protect against loss

Separate backup or archive strategy beyond basic retention


If the firm is dually registered, affiliated with a broker-dealer, or subject to FINRA rules, the analysis becomes stricter. Broker-dealer records may fall under SEC Exchange Act Rule 17a-4 and FINRA Rule 4511. Those rules can require electronic records to be preserved in a non-rewriteable, non-erasable format or maintained under an compliant audit-trail approach, along with indexing and prompt production.


Do not assume a standard Microsoft 365 retention policy satisfies those requirements by itself. The firm should confirm whether it needs WORM-style storage, a compliant audit-trail method, a third-party archive, or specific supervisory tooling.


Close-up view of labeled compliance binders and sealed evidence bags on a storage shelf
Retention periods are easier to enforce when records are classified before they scatter.

Start with a records map before changing settings


The most common mistake is turning on retention before deciding what counts as a record.


Start with a simple records map. It does not need to be fancy. It should answer four questions:


  1. Where do advisory business records live?

  2. Who owns each location?

  3. How long must each record category be retained?

  4. How would the firm retrieve it during an exam?


For most RIAs using Microsoft 365, the map should include:


  • Exchange Online mailboxes

  • Shared mailboxes

  • Microsoft Teams chats and channel messages

  • SharePoint sites

  • OneDrive accounts

  • Microsoft 365 Groups

  • Planner or Loop content, if used for business records

  • Marketing folders and approval history

  • Departed employee accounts

  • Third-party apps connected to Microsoft 365


This step often finds uncomfortable gaps. A portfolio manager may save client notes in OneDrive. A marketing associate may keep draft ads in a private folder. A service team may discuss client instructions in Teams, but the firm’s retention policy only covers email.


Do not skip those edge cases. Regulators generally care about the substance of the communication, not whether it happened in the “official” place.


Configure Microsoft Purview retention across the tenant


Microsoft Purview is the center of the compliance setup. This is where the firm can create retention policies, retention labels, eDiscovery workflows, audit settings, and communication review controls.


For many firms, the baseline is a tenant-wide retention policy for the core Microsoft 365 workloads:


  • Exchange email

  • Teams channel messages

  • Teams private chats

  • SharePoint sites

  • OneDrive accounts

  • Microsoft 365 Groups


The policy should match the firm’s retention schedule. For SEC adviser records, five years from the relevant fiscal year is the common baseline, but some firms retain longer based on state rules, FINRA obligations, litigation risk, insurance needs, or internal policy.


A practical setup often includes both broad policies and specific labels.


Use broad retention policies for communications


A broad retention policy can preserve email and Teams messages even if a user deletes them from their mailbox or chat view. That matters because user deletion should not control regulatory retention.


At minimum, review retention settings for:


  • User mailboxes

  • Shared mailboxes

  • Inactive mailboxes for former employees

  • Teams one-to-one and group chats

  • Teams channel messages

  • Microsoft 365 Groups connected to Teams


Teams deserves special attention. Staff may treat it like instant messaging, but a Teams chat about a client instruction, recommendation, complaint, performance figure, or account issue may be a business record.


Use retention labels for files and marketing materials


Retention labels help classify records by type. A firm might use labels for:


  • Client agreements

  • Investment policy statements

  • Performance reports

  • Advertisements and marketing materials

  • Compliance reviews

  • Trade support records

  • Complaint records

  • Client correspondence saved as files


For marketing materials, labels should preserve both the final approved version and evidence of review. If the firm uses SharePoint for marketing workflows, create a dedicated library with version history, restricted editing rights, approval steps, and a retention label that matches the compliance manual.


Be careful with Preservation Lock


Microsoft Purview includes Preservation Lock for certain retention policies. Once enabled, it prevents the policy from being turned off, deleted, or made less restrictive.


That can support immutability expectations, but it is not a setting to test casually. A misconfigured locked policy can preserve the wrong data for years and create cost, privacy, and operational problems.


Use this order:


  1. Build the policy in a test or limited scope.

  2. Confirm locations, retention duration, and exclusions.

  3. Review with compliance and legal.

  4. Document the reason for the lock.

  5. Enable only when the firm is ready to live with it.


Preserve email, Teams, SharePoint, and OneDrive together


SEC exam staff will not care that a client instruction started in email, moved to Teams, and ended as a SharePoint file. The firm needs the full chain.


That means retention cannot stop at Exchange.


Exchange Online


Email remains the core record source for most RIAs. Configure retention for all active mailboxes and shared mailboxes. Create a process for departed employees so their mailboxes become inactive mailboxes or are otherwise preserved before licenses are removed.


Also review mailbox forwarding rules, auto-delete rules, and external forwarding. These can create both security and recordkeeping concerns.


Microsoft Teams


Teams stores different content in different places. Chat messages, channel messages, meeting chats, files, and recordings may not all follow the same retention path.


Configure retention for:


  • Private chats

  • Group chats

  • Standard channel messages

  • Shared and private channel content

  • Files shared through Teams, which often live in SharePoint or OneDrive

  • Meeting recordings and transcripts, if used for advisory business


If the firm allows client communications through Teams, supervision and retention become even more important. Many advisers restrict client communications to approved channels for that reason.


SharePoint and OneDrive


SharePoint is usually better than OneDrive for firm records because it supports shared ownership, structured permissions, site-level retention, and document libraries. OneDrive is useful for individual work, but it can become a hidden archive of firm records.


A practical policy is to move official records into SharePoint libraries and limit OneDrive use for final business records. If OneDrive remains in scope, include it in retention, eDiscovery, and backup coverage.


Overhead view of a printed records map with colored strings connecting mail, chat, and file categories
A records map helps connect Microsoft 365 locations to regulatory obligations.

Lock down access and external sharing


Rule 204-2(g) expects electronic records to be limited to authorized personnel. Microsoft 365 access control should match that requirement.


Start with the basics:


  • Require multifactor authentication for all users.

  • Use Conditional Access for risky sign-ins and unmanaged devices.

  • Limit admin roles to the few people who need them.

  • Use separate admin accounts for privileged work.

  • Review guest users on a set schedule.

  • Block external forwarding unless approved.

  • Restrict anonymous sharing links in SharePoint and OneDrive.

  • Use sensitivity labels for confidential client and firm records.


SharePoint deserves a permission review. Many firms discover that old sites still allow broad access because someone clicked “share” years ago. Compliance records, client records, financial records, and marketing approval libraries should use groups, not one-off individual permissions.


Also review mobile access. If staff can download client records to personal devices, the firm needs device controls, app protection policies, or a clear exception process.


Turn on audit logs and eDiscovery before you need them


Audit and search settings are easy to ignore until an examination letter arrives. By then, gaps may already exist.


Microsoft Purview Audit can help the firm track user and administrator activity, including file access, sharing, deletion, mailbox activity, and configuration changes. Available features and retention periods can depend on licensing, so confirm what your tenant actually includes.


At minimum, the firm should be able to answer:


  • Who changed a retention policy?

  • Who deleted or restored a file?

  • Who shared a client folder externally?

  • Who accessed sensitive records?

  • When was a mailbox converted, removed, or preserved?

  • What search was run for a regulatory request?


Microsoft Purview eDiscovery should also be configured before an exam. Identify who can create cases, run searches, place content on hold, export results, and approve production. Keep those permissions tight.


A good test is simple. Pick a former employee, a client name, a date range, and a communication type. Then try to locate all related email, Teams messages, and files. If the search is slow, incomplete, or dependent on one person’s memory, the system is not exam-ready.


Add communication review where supervision is required


Retention preserves records. It does not supervise them.


For SEC advisers, compliance programs should address employee communications based on the firm’s business model and risks. For FINRA-regulated firms, supervision requirements are more formal, including review of certain communications under FINRA rules.


Microsoft Purview Communication Compliance can help review messages for policy matches, escalation, and documentation. It can be useful for:


  • Client complaints

  • Promissory language

  • Unapproved performance claims

  • Use of testimonials or endorsements

  • Personal email addresses

  • Prohibited communication channels

  • Sensitive data exposure


This tool should be tuned carefully. Too many false positives can bury reviewers. Too few review categories can miss real problems.


Pair the tool with a written procedure that explains:


  • What gets reviewed

  • Who reviews it

  • How often review occurs

  • How exceptions are escalated

  • How evidence of review is retained


The procedure matters as much as the software. A regulator may ask not only whether review tools exist, but how the firm uses them.


Use backup as a separate safety net


Microsoft retention is not the same as a separate backup.


Retention helps preserve records under policy. Backup helps recover data after accidental loss, malicious deletion, ransomware, software failure, or other disruption. Rule 204-2(g) also speaks in terms of separate backup for electronic records.


Some firms use Microsoft-native recovery features plus a third-party backup or archive. Others use a dedicated compliance archive for email, Teams, and files. The right choice depends on the firm’s registration status, FINRA exposure, risk tolerance, and counsel’s view of the rules.


Whatever approach the firm chooses, test it. A backup that has never been restored is only an assumption.


Set a schedule to test recovery for:


  • A deleted mailbox

  • A former employee’s records

  • A SharePoint library

  • A Teams conversation or related files

  • A marketing approval folder

  • A specific regulatory search request


Document the results. If a test fails, fix the process and test again.


Eye-level view of a fireproof safe with a backup drive case and printed restore checklist
Separate backups protect the firm when retention alone is not enough.

Document the configuration and review it regularly


A Microsoft 365 compliance setup is not finished when the policies are turned on. The firm needs evidence that the setup matches its written compliance program.


Keep a configuration record that includes:


  • Retention policies and locations covered

  • Retention labels and file plan

  • Preservation Lock decisions

  • eDiscovery roles

  • Audit log settings

  • Communication review procedures

  • External sharing settings

  • Admin role assignments

  • Backup scope and test results

  • Exceptions and approvals


Review the setup at least annually and whenever the firm changes how it works. New Teams, new SharePoint sites, new marketing tools, mergers, departed employees, and new client communication channels can all create recordkeeping gaps.


The best Microsoft 365 SEC Compliance Guide for Investment Advisers is not a one-time checklist. It is a control system that reflects how the firm actually communicates.


What a compliant setup should look like


A well-configured Microsoft 365 environment should make compliance easier in daily work, not harder.


The target state looks like this:


  • Business email, Teams messages, SharePoint files, and OneDrive records are covered by retention.

  • Marketing materials have a controlled review and preservation process.

  • Users cannot erase required records just by deleting them.

  • Former employee records remain searchable.

  • Access is limited to the right people.

  • External sharing is controlled and reviewed.

  • Audit logs show meaningful activity.

  • eDiscovery can find communications across workloads.

  • Separate backups can be restored.

  • The firm has written evidence of all key settings and tests.


Microsoft 365 will not make an advisory firm compliant on its own. No software will. But with the right Purview policies, access controls, audit settings, supervisory workflows, and backups, it can become a strong foundation for meeting SEC and FINRA recordkeeping expectations.


The next step is simple: compare your written retention schedule to your actual Microsoft 365 configuration. If the two do not match, fix the system before an examiner is the person who finds the gap.


 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
Featured Posts
Recent Posts
Archive
Search By Tags
Follow Us
  • Facebook Basic Square
  • Twitter Basic Square
  • Google+ Social Icon
bottom of page