Pittsburgh CPA Firm SOC 2 and Microsoft 365 Copilot Case Study

PGH Networks is a Pittsburgh-based managed services provider that helps accounting, professional services, and regulated mid-market firms across the Pittsburgh metro run secure IT, meet compliance frameworks like SOC 2, and adopt AI safely. This Pittsburgh CPA firm SOC 2 and Microsoft 365 Copilot case study describes an anonymized engagement with a regional public accounting firm headquartered in the South Hills, with satellite offices in Cranberry Township and Greensburg.
The firm is roughly 55 people: partners, tax and audit staff, a small advisory group, and back-office admins. They serve closely held businesses across Allegheny, Butler, Washington, and Westmoreland counties, and a handful of SEC-adjacent clients that started asking harder questions about how their tax and audit workpapers are protected.
The scenario: a growing Pittsburgh CPA firm
Two of the firm's larger advisory clients had renewed their vendor risk questionnaires and now required a SOC 2 Type II report from any external accountant handling their financial data. At the same time, three partners had been personally experimenting with ChatGPT for drafting client memos, and the managing partner was worried about tax return data ending up in a public model. The firm's prior IT provider handled break-fix and Microsoft 365 licensing competently but had no compliance practice and no point of view on generative AI.
They came to us wanting one partner who could do both: get them through a SOC 2 examination on a nine-month timeline and stand up a governed Microsoft 365 Copilot deployment their staff could actually use during busy season.

The challenge: SOC 2 pressure and AI curiosity at the same time
On the compliance side, the firm had the usual gaps of a professional services shop that had grown organically. MFA was enforced for email but not for the tax application or the file server VPN. Endpoint protection was consumer-grade AV. There was no formal vendor management program, no documented access review cadence, and no SIEM or centralized logging, which meant the CC7 (system operations) and CC6 (logical access) trust services criteria were effectively unauditable.
On the AI side, the risk was subtler. Copilot for Microsoft 365 inherits the permissions of the user invoking it, and this firm had years of accumulated SharePoint and OneDrive sprawl. Partner compensation spreadsheets, HR files, and prior-year 1040s were all reachable by broader groups than anyone realized. Turning Copilot on without remediating that surface would have created a data-exposure incident on day one.
Copilot doesn't leak data, over-permissioned SharePoint does, and every CPA firm we've assessed has more of it than they think.
How it was solved: SOC 2 readiness plus a governed Copilot rollout
We ran the engagement as two coordinated tracks under a single vCIO plan, so the SOC 2 work and the AI work reinforced each other rather than competing for calendar time.
TL;DR: SOC 2 remediation and a safe Copilot rollout are the same project — both depend on identity, least-privilege access, logging, and written policy.
The compliance track started with a gap assessment mapped to the AICPA Trust Services Criteria (the CC-series controls). From there we executed the remediation: Microsoft 365 Business Premium tenant hardening with Conditional Access and phishing-resistant MFA, migration off the legacy VPN to Entra-joined devices, an EDR rollout with 24x7 MDR monitoring, centralized log collection into a SIEM with 12-month retention, formal change management and access-review procedures, and a vendor management program covering the firm's tax, audit, and payroll software. We wrote the policy set — information security, incident response, acceptable use, BCDR — and handed a clean control environment to an independent auditor for the Type I, then supported the six-month observation window to Type II. Our managed IT team owned patch management, RMM, and help desk throughout so partners weren't chasing tickets during 1040 season.
The AI track began with a Copilot readiness assessment focused on data governance. Before a single Copilot license was activated we remediated SharePoint permissions using Microsoft Purview sensitivity labels, applied "Confidential — Tax Client Data" and "Confidential — Firm Internal" labels to the roughly 40 sites that mattered, and turned on DLP policies that block Copilot from surfacing labeled content to users outside the engagement team. We wrote an AI acceptable-use policy the partners could actually defend to clients, then piloted Copilot with eight users across tax and audit. Once the pilot held, our AI advisory team designed two firm-specific workflows — an engagement-letter drafter and a workpaper review summarizer — delivered as a lightweight custom AI application sitting on Azure OpenAI inside the firm's own tenant, so no client data leaves the compliance boundary.
Outcomes: audit-ready controls and measurable AI lift
The firm received an unqualified SOC 2 Type I report at month five and completed the Type II observation window on schedule. The two advisory clients that had triggered the project accepted the report and renewed. A third client, previously served under a carve-out arrangement, moved additional work to the firm on the strength of the report.
On the AI side, Copilot adoption reached 78% weekly active use across licensed staff within 90 days — well above the roughly 40% adoption our AI team typically sees in ungoverned rollouts, because the sensitivity-label work meant Copilot answers were actually relevant instead of noisy. The engagement-letter workflow cut first-draft time from about 45 minutes to under 10. The workpaper summarizer is being expanded to a broader AI workflow automation footprint in the current fiscal year.
Just as important: zero data-loss incidents during or after rollout, and the SIEM caught two credential-stuffing attempts against partner accounts in the first quarter of monitoring, both blocked by Conditional Access.

Takeaway for other Pittsburgh accounting firms
If you run a Pittsburgh-area CPA firm and you're being pushed toward SOC 2 by your own clients while your partners quietly paste tax data into consumer AI tools, treat these as one project, not two. The identity, access, logging, and policy work that satisfies a SOC 2 auditor is exactly the work that makes Microsoft 365 Copilot safe to deploy. Sequenced correctly under a single vCIO roadmap, a mid-sized firm can be Type II ready and Copilot productive inside a single fiscal year without disrupting busy season.
This Pittsburgh CPA firm SOC 2 and Microsoft 365 Copilot pattern is repeatable, and it's what we do.
Talk to PGH Networks
Call 724.888.7007 or reach us through the contact form to scope a SOC 2 gap assessment and Copilot readiness review for your firm.
Related reading

Managed IT for Pittsburgh CPA Firms: SOC 2 and AI Enablement
How Pittsburgh CPA firms should evaluate managed IT for SOC 2 readiness and AI workflow enablement, and how PGH Networks combines both under one roof.

Managed IT and AI Enablement for Pittsburgh CPA Firms
How Pittsburgh CPA firms should evaluate an MSP for SOC 2 readiness, IRS Pub 4557, GLBA Safeguards, and AI workflow enablement including Copilot for Finance.

Cyber Insurance Requirements Pittsburgh: MSP Compliance Guide
Struggling to meet cyber insurance requirements in Pittsburgh? See what carriers now demand: MFA, EDR, backups, IR plans, and how a local MSP helps you qualify.