Microsoft 365 satisfies all FINRA/17a-4 requirements
Microsoft Purview (included in Business Premium) provides WORM-compliant archiving with a CFTC/SEC 17a-4 compliance attestation from Cohasset Associates. The majority of FINRA-registered broker/dealers run on Exchange Online. FINRA has published guidance explicitly endorsing cloud-based recordkeeping.
Action item (BLOCKER)
Sheila has been asked to produce written policy from the Broker/Dealer that explicitly names Intermedia as the required platform. This policy is expected not to exist — the B/D policy will require compliant archiving, not a specific vendor. Resolution expected before meeting 2026-05-27 14:00.
Recommended Architecture: M365 Business Premium + Mailprotector
License Plan
Account
License
Domain
John (firm)
M365 Business Premium
quantumwms.com
Sheila (firm)
M365 Business Premium
quantumwms.com
Sheila (personal)
Exchange Online Plan 1
sheilaperess.com
Others TBD
Exchange Online Plan 1
TBD
What Business Premium provides over Intermedia
Capability
Intermedia Hosted Exchange
M365 Business Premium
Email
Exchange Server (hosted)
Exchange Online (Microsoft cloud)
Exchange CVE exposure
YES — full Server CVE surface
No — Microsoft patches same-day
Spam/malware filtering
Basic
Defender for Office 365 Plan 1 (Safe Links, Safe Attachments)
Frontend filtering
None
Mailprotector (ACG-managed)
MFA enforcement
Manual
Entra ID P1 — Conditional Access
FINRA archiving
Intermedia archiver (extra cost)
Microsoft Purview — included
Desktop Office apps
No
Yes (Word, Excel, Outlook, etc.)
Mobile device management
No
Intune — included
DMARC/DKIM setup
Not managed
ACG-managed during migration
Migration Steps
[DONE] Get consent from John (2026-05-26)
Obtain written B/D compliance policy from Sheila — confirm no Intermedia mandate
Add quantumwms.com as verified domain to johnvelez.com tenant