Protecting your firm's data requires more than a single setting or configuration — it demands a layered, proactive approach. This article brings together the key identity management and security features available in Neos to help your firm establish consistent safeguards, reduce risk, and maintain a strong security posture over time — so you can have confidence that client data is protected at every level.
Strengthen Your Security Posture with Neos
The strongest security starts with identity. By leveraging modern identity management alongside the built-in security features in Neos, your firm can build a defense-in-depth strategy that protects client data at every layer.
Start with Microsoft Entra
The foundation of a strong security posture is centralizing identity management through Microsoft Entra ID (formerly Azure Active Directory). Neos supports enterprise Single Sign-On through both Microsoft 365 and SAML 2.0, allowing your firm to authenticate users through your corporate identity provider.
When Neos is connected to Entra ID, you unlock the full power of Microsoft's identity security platform:
Phishing-resistant MFA — Enforce modern multi-factor authentication methods such as FIDO2 security keys, Windows Hello for Business, or Microsoft Authenticator push notifications. These methods are resistant to phishing, token theft, and man-in-the-middle attacks — far stronger than traditional SMS codes.
Conditional Access policies — Define rules that control how and when users can access Neos based on real-time conditions:
• IP allow/deny lists — Restrict logins to your office network, VPN, or other trusted IP ranges. Block access from unknown or high-risk locations.
• Region allow/deny lists — Permit access only from countries where your firm operates and block sign-in attempts from regions where you have no business presence.
• Device compliance — Require that devices meet your firm's security standards (managed, encrypted, up-to-date) before granting access.
• Risk-based access — Automatically challenge or block sign-ins that Microsoft's AI detects as risky, such as logins from unfamiliar devices, impossible travel scenarios, or known attacker infrastructure.
Identity alert monitoring with Microsoft Defender — Gain visibility into suspicious activity targeting your firm's accounts. Microsoft Defender for Identity detects credential attacks, lateral movement attempts, and anomalous sign-in behavior, alerting your administrators before a breach occurs.
Neos supports firm-wide SSO enforcement, meaning administrators can require all staff to log in exclusively through your Entra ID tenant. This ensures that when an employee is offboarded in Entra ID, their Neos access is revoked immediately — no manual cleanup required.
Recommended: Connect Neos to your Microsoft Entra ID tenant, enforce SSO-only login, and configure Conditional Access policies with phishing-resistant MFA. This single step dramatically reduces your firm's attack surface.
Restrict Login Domains
Neos allows administrators to maintain an approved login domain list, restricting authentication to specific email domains (e.g., @yourfirm.com). Any login attempt from an unapproved domain is automatically blocked at the server level, regardless of whether the credentials are valid.
Recommended: Enable approved login domains immediately, even if you have SSO configured. This provides an additional layer of defense against unauthorized access.
When SSO Is Not an Option: Strong Passwords with Two-Factor Authentication
If your firm is not yet using SSO through Entra ID, securing Neos accounts with strong passwords and two-factor authentication is essential.
Neos enforces the following password requirements on all accounts:
Minimum 8 characters
Must include uppercase and lowercase letters, at least one number, and a special character
All passwords are stored using Argon2 hashing — a modern, one-way cryptographic algorithm that cannot be reversed, even in a breach scenario
In addition, Neos provides built-in two-factor authentication (2FA):
When enabled, users must enter a one-time verification code after providing their password
Codes are delivered via SMS text message or email
Users can mark trusted devices to reduce friction for 30 days
Administrators can enforce 2FA firm-wide with a single toggle under Settings > Firm Preferences > Security
Recommended: If SSO is not available, enforce firm-wide 2FA immediately. Two-factor authentication is the single most effective defense against account compromise from stolen or weak passwords.
Access Control and Ongoing Security Hygiene
Security is not a one-time configuration — it requires ongoing attention. Use these built-in Neos features and operational practices to maintain a strong security posture over time.
Configure Group-Based Permissions
Neos provides a robust, role-based permissions framework that should be configured using Permission Groups rather than individual user settings.
Navigate to the Permission Groups page to create security roles tailored to your firm's structure (e.g., Attorney, Paralegal, Intake Coordinator, Accounting, Firm Administrator)
Each group controls access across over 70 permission areas with view, add, modify, and delete levels, plus 45 special permissions for sensitive operations such as exporting data, generating documents, modifying closed cases, and using AI features
Assign each staff member to the appropriate group based on their role — permissions are applied consistently and can be updated for an entire role in one place
Recommended: Never assign permissions to individual users. Always use Permission Groups so that access is consistent, auditable, and easy to update when roles change.
Configure Case-Level Restrictions
For firms that need to enforce ethical walls or conflict-of-interest boundaries, Neos supports case-level and case-type-level access restrictions.
Forbidden Cases — Block specific staff members or permission groups from viewing or accessing particular cases
Forbidden Case Types — Restrict entire categories of cases from specific staff or groups
These restrictions are enforced at the server level — restricted users cannot access the data through any part of the application.
Recommended: Configure case restrictions proactively when conflicts are identified. Do not rely on staff to self-police access to sensitive matters.
Audit Group Membership and User Access Regularly
Access controls are only effective if they stay current. Establish a regular cadence for reviewing who has access to Neos and what they can do.
Review Permission Group membership quarterly — Confirm that each staff member is assigned to the correct role and that no one has been granted excessive permissions
Deactivate departed staff immediately — When an employee leaves the firm, disable their Neos account the same day. If SSO is enabled, disabling their Entra ID account accomplishes this automatically
Review case restrictions — Ensure ethical walls and conflict restrictions are up to date as matters evolve
Audit administrator-level accounts — Limit the number of users with full administrative access. Administrators should be senior, trusted staff only
Recommended: Assign a specific person (office manager, IT administrator, or firm administrator) as the owner of quarterly access reviews.
Conduct Regular Staff Training and Phishing Simulations
Technology alone cannot prevent all security incidents. Human error — particularly falling for phishing attacks — remains the leading cause of security breaches in law firms.
Train all staff on recognizing phishing emails — Teach your team to identify suspicious sender addresses, urgent language designed to bypass judgment, and links that don't match their expected destination
Run phishing simulations regularly — Use tools such as Microsoft Defender for Office 365 Attack Simulation or similar platforms to send simulated phishing emails to your team. Track who clicks, provide immediate coaching, and measure improvement over time
Reinforce that credentials should never be shared — No legitimate service, including Neos and Assembly Software Support, will ever ask for a user's password
Report suspicious activity promptly — Establish a clear process for staff to report suspected phishing attempts or unusual account behavior
Recommended: Conduct phishing simulations at least quarterly. Firms that run regular simulations see significant reductions in staff susceptibility to real phishing attacks over time.
Security is a shared responsibility. Assembly Software secures the Neos platform with enterprise-grade Azure infrastructure, encryption, and monitoring. Your firm controls identity, access, and user behavior. Together, these layers provide comprehensive protection for your clients' most sensitive information.
For assistance configuring SSO, MFA, approved domains, or any other security feature in Neos, contact Assembly Software Support or your dedicated account representative.
