Microsoft 365 for CPA and Accounting Firms: IRS Publication 4557, the Written Information Security Plan, and the Controls That Satisfy Both
A CPA firm is a financial institution under the FTC Safeguards Rule, and the IRS says so in plain words in Publication 4557. That makes two regulators, one written plan and a checkbox on every PTIN renewal. The good news for a firm on Microsoft 365 is that most of the required controls are settings in a tenant it already pays for. This article lists what the IRS and the FTC ask, maps each ask to a Microsoft 365 control and its evidence, and covers the two things specific to a tax practice: the January to April load and the client portal. The WISP outline itself is in our [FTC Safeguards checklist and WISP outline](/blog/ftc-safeguards-rule-checklist-and-wisp-outline-for-microsoft-365).
What the IRS and the FTC ask of a tax practice
The FTC Safeguards Rule (16 CFR Part 314) reaches tax preparation and accounting firms as non-bank financial institutions. As we read the amended rule, in force since June 2023, it asks for nine things: a Qualified Individual, a written risk assessment, eight named safeguards (among them MFA for anyone accessing any information system, encryption, access controls, disposal, and logging and monitoring), testing, training, service-provider oversight, a program kept current, a written incident response plan and an annual report to the board. Since 13 May 2024 a breach of unencrypted information on 500 or more consumers must be reported to the FTC within 30 days of discovery. Firms holding data on fewer than 5,000 consumers skip some paperwork, not MFA or encryption.
IRS Publication 4557, "Safeguarding Taxpayer Data," is the IRS guide to that same obligation for tax professionals. As reported in search results on 27 September 2026 (verify on irs.gov), the current revision dates from June 2024, it lists the "Security Six" (antivirus, a firewall, multi-factor authentication, backups, drive encryption and a VPN for remote work), and it requires a written information security plan. Publication 5708 is the IRS template for that plan; trade reports of the August 2024 update say it added the MFA requirement and the 500-person FTC reporting duty (as reported by CPA Practice Advisor, 29 July 2025). Form W-12, the PTIN application and renewal, carries a line asking the preparer to confirm awareness of the legal obligation to have a data security plan (as reported).
Mapping the requirements to Microsoft 365 controls
Each requirement below names the control and the evidence a reviewer will accept. The FTC Safeguards article has the full element-by-element table; this list keeps the CPA-specific reading.
- MFA for anyone accessing any information system. Conditional Access requiring MFA for every user, including partners, seasonal staff and the shared "returns" mailbox, with legacy authentication blocked.
- Antivirus and EDR. Defender for Business on every laptop, onboarded through Intune.
- Firewall. The Windows firewall enforced by Intune policy plus the office firewall, both recorded.
- Drive encryption. BitLocker required by Intune compliance, with recovery keys escrowed in Entra.
- Backups. Microsoft 365 data needs its own backup; native versus third-party backup covers the choice. Evidence: a restore test dated before tax season.
- Remote access. For an all-cloud firm, Conditional Access on compliant devices does the job Publication 4557 gives a VPN; if a server or hosted tax application remains, use a VPN or Entra Private Access and say which in the plan.
- Access controls and disposal. Least-privilege roles in Entra, quarterly access review, and Purview retention with disposal at the end of the period your state and the IRS require.
- Logging and monitoring. Purview audit turned on with retention that outlasts an audit period, Defender alerts routed to a person, and the DLP override log.
- Data inventory and DLP. Sensitivity labels for client documents and the DLP policies in our Purview DLP starter set, starting with Social Security and bank numbers leaving to personal email.
- Training and incident response. Annual training with a record per person, and a written plan naming the IRS Stakeholder Liaison contact and the FTC procedure. The cyber insurance questionnaire article shows the same evidence answering the insurer.
Licensing: what Business Premium covers, and the add-on a firm may need
Microsoft 365 Business Premium ($264.00 per user per year, Microsoft list price, September 2026 price list) carries every control above except the third-party backup: Entra ID P1 for Conditional Access, Intune Plan 1 for compliance and encryption, Defender for Business, Defender for Office 365 Plan 1 for phishing protection, and Purview Information Protection with DLP for email and files (Microsoft Learn, 24 September 2025). A 12-person firm is $3,168 a year; a 40-person firm is $10,560.
The one gap that matters for a tax practice is endpoint DLP: stopping a return from being copied to a USB stick or printed at home needs Microsoft 365 E5 Information Protection and Governance at $84.00 per user per year (Microsoft list price, September 2026 price list), licensed for the people who prepare returns on laptops. A 40-person firm adding it for 15 preparers pays $1,260 a year.
Tax season: the load, and the controls that must not get in the way
Between January and April the firm doubles its email, adds seasonal preparers, and cannot afford a locked-out partner on 14 April. Four decisions decide whether security survives.
- Phishing-resistant sign-in before January. Push-notification MFA fails under fatigue. Move partners and preparers to passkeys or Windows Hello for Business in the fall, in the order our passkeys rollout article gives.
- Seasonal staff on a clock. Create accounts with an end date, assign a Business Premium license, enroll the laptop through Autopilot, and let the lifecycle workflow disable the account on the last day.
- A change freeze with a break-glass account. No Conditional Access edits from mid-January to mid-April except emergencies, and two break-glass accounts excluded from every policy and tested in December.
- A restore drill in December. Restore a client folder and a mailbox before the season and keep the ticket; it is the backup evidence the WISP needs.
The same month, run the Microsoft 365 Security Audit, Baseline ($525 per project, three days) so the settings above are verified rather than assumed.
The client portal question: SharePoint sharing or a portal product
Clients need to send W-2s and 1099s and receive a return, and email is the wrong place for both.
SharePoint and OneDrive external sharing is included in the license. Share with specific people, require the recipient to verify with a one-time passcode or a Microsoft account, label the folder Confidential, and let DLP block the "Anyone" link. The cost is client experience: a passcode step, no e-signature, no organizer questionnaire, no payment collection. The law firm SharePoint article shows the per-client structure that makes this workable.
A portal product from the tax software vendor adds e-signature for Form 8879, organizers, invoicing and a familiar client login, and it is licensed per firm or per return; pricing models vary, so check the vendor. It is a separate information system: it needs MFA, its own logging, a vendor risk entry in the WISP and a contract clause on breach notice.
Our usual answer for a firm under 50 people: the portal for the return cycle, SharePoint for the year-round engagement files, and a written rule that no client data lives in email. Whichever holds returns is listed in the WISP with its MFA and logging evidence.
Frequently asked questions
Does the IRS require a WISP for tax preparers?
The IRS states that paid tax preparers are required by federal law, through the FTC Safeguards Rule, to have a written information security plan, and Form W-12 asks each preparer to confirm awareness of the obligation at PTIN renewal (as reported; verify on irs.gov). Publication 5708 is the IRS template.
Is Microsoft 365 compliant with IRS Publication 4557?
No product is. Publication 4557 describes controls; Microsoft 365 Business Premium contains the settings that implement most of them, and compliance is the firm's plan, the settings turned on, and the evidence kept.
Do we need MFA for the tax software as well as Microsoft 365?
Yes. The Safeguards Rule asks for MFA for anyone accessing any information system, and the tax application, the portal and the practice management system are information systems. List each with its MFA status in the WISP, with the Qualified Individual's written exception where a vendor cannot.
What do we do after a data theft?
Contain the account, then follow the plan: contact the IRS Stakeholder Liaison for your state (as the IRS asks; verify the current process on irs.gov), notify the FTC within 30 days if unencrypted information on 500 or more consumers was taken, follow state breach law, and keep the timeline. What a post-incident report should contain shows the document you will need.
Sources
- FTC Safeguards Rule, 16 CFR Part 314: elements, dates and thresholds as read in our FTC Safeguards article and readiness assessment page (an engineering reading, not legal advice; ftc.gov and ecfr.gov were not reachable from our writing environment)
- IRS Publication 4557 and Publication 5708 (not opened; the June 2024 revision, the Security Six and the August 2024 template update as summarized in search results and as reported by CPA Practice Advisor on 29 July 2025; verify on irs.gov)
- IRS Form W-12 and its instructions (revised October 2025 per search results; the data security awareness line as reported; verify on irs.gov)
- Microsoft Learn, "Add Microsoft Defender Suite for Business Premium to your subscription" (ms.date 24 September 2025; opened via the MicrosoftDocs GitHub source): Business Premium contents
- Microsoft, "Microsoft Purview licensing guidance" (opened 27 September 2026): endpoint DLP licensing
- Microsoft, Commercial price list, September 2026 (our CSP price sheet)
- IT Partner blog: ftc-safeguards-rule-checklist-and-wisp-outline-for-microsoft-365; cyber-insurance-questionnaire-the-microsoft-365-evidence-that-answers-each-question; sharepoint-compliance-structure-law-firms; passkeys-phishing-resistant-mfa-microsoft-365-rollout-order
- IT Partner engineering notes from accounting-firm tenants, September 2026
| Requirement (Publication 4557 and 16 CFR 314.4) | Microsoft 365 control | Evidence to keep | License |
|---|---|---|---|
| MFA for every information system | Conditional Access requiring MFA; legacy auth blocked; vendor MFA list | Policy export; registration report | Business Premium |
| Antivirus and EDR | Defender for Business via Intune | Device health list; alert history | Business Premium |
| Drive encryption | BitLocker compliance policy | Encryption report | Business Premium |
| Backups | Microsoft 365 backup product | December restore ticket | Separate |
| Access control and disposal | Entra roles; access review; Purview retention | Role list; review record; retention policy | Business Premium |
| Logging and monitoring | Purview audit; Defender alerts; DLP log | Audit export; tickets | Business Premium |
| Data leaving the firm | DLP for email and files; endpoint DLP | Policy list; override log | Business Premium; E5 Information Protection and Governance for devices |
| Written plan, training, vendors, incident response | Not a setting | WISP; training records; vendor list; plan | None |
Key takeaways
- A CPA firm answers to two regulators for the same controls: the FTC Safeguards Rule and IRS Publication 4557, with the WISP as the single document and Form W-12 as the annual attestation.
- Microsoft 365 Business Premium contains the settings for MFA, EDR, encryption, access control, logging and DLP; backup and the written program are separate.
- Endpoint DLP for returns on laptops is the one add-on most firms need, at $84.00 per user per year for the preparers (Microsoft list price, September 2026 price list).
- Tax season is survived by decisions made in the fall: passkeys, seasonal accounts with end dates, a change freeze with tested break-glass accounts, and a December restore drill.
- Use the vendor portal for the return cycle and SharePoint for engagement files, and list both in the WISP with their MFA and logging evidence.
The FTC Safeguards Rule (GLBA) Readiness Assessment ($3,950 per project, three weeks) records the coverage position, maps each safeguard to your tenant with the evidence exported, and hands you the gap report and the WISP outline that Publication 4557 and Form W-12 assume you have. Before the season, the Microsoft 365 Security Audit, Baseline ($525 per project, three days) verifies MFA, device and sharing settings; Enable MFA for All Users ($700 per project) closes the first gap if it is open. After the plan exists, the Compliance Evidence and Audit Readiness Retainer ($950 per month) collects the monthly evidence so the next renewal checkbox is true. Licenses are at Microsoft's list price on our Microsoft 365 Business Premium page. We are Microsoft 365 engineers, not a law firm; nothing here certifies compliance.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.