Entra ID is the obvious core choice, and you're right to start there. But for a firm with their compliance needs, you need to build the DLP and logging policies *right into that initial identity design*, not bolt them on later.
Think about this: a policy that grants access to NetDocuments based on Entra ID group membership is step one. Step two, which should be drafted in parallel, is the data profile that scans every download from that app for specific client matter numbers or privileged patterns, then logs the event to a separate SIEM for the compliance team. That's the only way to meet "baked into every connection."
Also, for the partners who hate friction, make sure your conditional access policies have a clear, tested "break-glass" flow. If a rainmaker can't access a critical doc before a filing deadline because of a device compliance hiccup, your beautiful zero-trust model will get an exception carved straight through it.
Happy testing!