Access and governance
Microsoft 365 Access and Account Review
When a former employee, provider or MFA phone still holds the key, the next correction starts with knowing who can act.
The account causing the concern
Start with the access that needs a decision
A former employee may still be active, but nobody knows how to remove the access safely.
A shared administrator account exists without a clearly accountable owner.
The phone used for multi-factor verification belongs to one person.
Nobody knows which accounts can change billing, security or access.
Why this becomes urgent
Access without an owner is hard to remove safely
An account without an owner becomes an urgent business decision. The review establishes who can act, how access can be recovered and which dependencies must remain in place before a role changes or an account is closed.
Common situations
- The only global administrator is still controlled by a provider who no longer responds.
- A shared mailbox or important Teams site has no business owner.
- One person knows the password, but recovery depends on a former phone.
- An emergency account exists, but nobody knows how to verify that it can be used.
What we check
Connect accounts to real responsibility
- Users, administrator accounts, privileged roles and inactive accounts within the agreed scope.
- Multi-factor verification and recovery methods, without collecting secrets.
- Rules that can require stronger verification in a given situation — what Microsoft calls Conditional Access.
- Mailboxes, Teams or SharePoint spaces, app consent and forwarding rules whose owner needs confirmation.
You leave with
Decisions management can explain
- A map of known accounts, confirmed owners and unknowns.
- Clear decisions for administrators, emergency accounts and recovery paths.
- A prioritized correction list separated from changes requiring a different technical scope.
- A summary usable for a one-time decision without creating a recurring review obligation.
A focused review
What is included and what needs another scope
In the review
- A technical review of the agreed users, access and shared spaces.
- Identification of administrator roles, MFA methods and missing owners.
- Plain-language notes that separate an observation, a decision and a possible correction.
Handled separately
- Configuration, remediation, licence changes or account cleanup.
- Legal advice, certification or compliance advice.
- Ongoing administration, monitoring or recurring management of the environment.
Scope, deliverables, and pricing are confirmed before work begins. Additional work requires approval.
Before access is opened
Scope comes before verification
We confirm the scope, evidence, customer responsibilities and any licences or third-party costs before changes are considered.
What the business confirms
- Approve the scope, access and people who can confirm responsibilities.
- Provide available information without sending secrets into the register.
- Confirm business owners and the accounts that must remain recoverable.
A useful next conversation
Decide who controls Microsoft 365
Tell us what is happening. Initial contact confirms the right scope and requirements; it does not authorize a change.
Decide who controls Microsoft 365