A Houston-based healthcare operator with 27 facilities across 12 states disclosed earlier this month that patient and employee information was stolen in an August ransomware attack.
Most practices I work with in Palm Beach and Martin County aren't that size. But plenty of them grew the same way — a second office here, an acquired practice there — and each location showed up with its own Microsoft 365 setup. Different password rules. Different admin accounts. Different idea of what "secure" means.
The real problem isn't that one office is weaker than the others. It's that nobody can tell which one. When I ask a three-location group who has multi-factor authentication turned on everywhere, the honest answer is usually a shrug.
Microsoft built a tool for exactly this, and it costs your IT provider nothing extra. Microsoft 365 Lighthouse puts every location on one screen: who is actually registered for MFA, which laptops have drifted out of line with your security policies, which accounts have gone dormant, and a security score for each office you can line up side by side.
That last part is what matters. You stop guessing which location is the weak one — and you find out before an attacker does, or before your carrier asks at renewal.
If you run more than one office under more than one Microsoft tenant, it's worth asking your IT provider whether they're using it.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email