Access and governance

Microsoft 365 Access and Account Review

When a former employee, provider or MFA phone still holds the key, the next correction starts with knowing who can act.

Decide who controls Microsoft 365 Read the security guide

The account causing the concern

Start with the access that needs a decision

A former employee may still be active, but nobody knows how to remove the access safely.

A shared administrator account exists without a clearly accountable owner.

The phone used for multi-factor verification belongs to one person.

Nobody knows which accounts can change billing, security or access.

Why this becomes urgent

Access without an owner is hard to remove safely

An account without an owner becomes an urgent business decision. The review establishes who can act, how access can be recovered and which dependencies must remain in place before a role changes or an account is closed.

Common situations

  • The only global administrator is still controlled by a provider who no longer responds.
  • A shared mailbox or important Teams site has no business owner.
  • One person knows the password, but recovery depends on a former phone.
  • An emergency account exists, but nobody knows how to verify that it can be used.

What we check

Connect accounts to real responsibility

  • Users, administrator accounts, privileged roles and inactive accounts within the agreed scope.
  • Multi-factor verification and recovery methods, without collecting secrets.
  • Rules that can require stronger verification in a given situation — what Microsoft calls Conditional Access.
  • Mailboxes, Teams or SharePoint spaces, app consent and forwarding rules whose owner needs confirmation.

You leave with

Decisions management can explain

  • A map of known accounts, confirmed owners and unknowns.
  • Clear decisions for administrators, emergency accounts and recovery paths.
  • A prioritized correction list separated from changes requiring a different technical scope.
  • A summary usable for a one-time decision without creating a recurring review obligation.

A focused review

What is included and what needs another scope

In the review

  • A technical review of the agreed users, access and shared spaces.
  • Identification of administrator roles, MFA methods and missing owners.
  • Plain-language notes that separate an observation, a decision and a possible correction.

Handled separately

  • Configuration, remediation, licence changes or account cleanup.
  • Legal advice, certification or compliance advice.
  • Ongoing administration, monitoring or recurring management of the environment.

Scope, deliverables, and pricing are confirmed before work begins. Additional work requires approval.

Before access is opened

Scope comes before verification

We confirm the scope, evidence, customer responsibilities and any licences or third-party costs before changes are considered.

What the business confirms

  • Approve the scope, access and people who can confirm responsibilities.
  • Provide available information without sending secrets into the register.
  • Confirm business owners and the accounts that must remain recoverable.

A useful next conversation

Decide who controls Microsoft 365

Tell us what is happening. Initial contact confirms the right scope and requirements; it does not authorize a change.

Decide who controls Microsoft 365