Home / Blog

How to Audit Microsoft 365 Permissions Properly

A former employee can still open a SharePoint folder. A contractor can retain access to a project Team long after handover. A global administrator account may be used for routine work because nobody has reviewed role assignments. These are common operational gaps – and exactly why knowing how to audit Microsoft 365 permissions matters.

For most organisations, the issue is not that Microsoft 365 lacks security controls. It is that access has accumulated over time. Staff change roles, projects finish, devices are replaced and external collaborators come and go. Unless permissions are reviewed with a clear process, old access becomes invisible risk.

A good permission audit gives management a practical answer to three questions: who can access business information, what can they do with it, and is that access still justified? It also creates evidence for internal governance, client requirements and security frameworks such as the Essential Eight.

Why Microsoft 365 permission audits need a business focus

A permission audit is not simply a technical clean-up. It is a control over business risk, productivity and accountability. Excessive access increases the potential impact of a compromised account. Missing access can stop staff from doing their work. The right result is not to remove every permission possible. It is to give each person the minimum access needed to perform their role.

This is known as least-privilege access. In practice, it means a payroll officer should not automatically have access to HR case files, a site supervisor should not administer tenant-wide settings, and an external consultant should not remain in Teams after their engagement ends.

For small and mid-sized organisations, permissions are often managed by different people at different times. An office manager may add a user to a Team, a department head may share a folder, and an IT provider may assign an administrative role. The audit brings those decisions into one accountable view.

What to include when you audit Microsoft 365 permissions

Microsoft 365 permissions sit in several places. Reviewing only the Microsoft 365 admin centre will miss a significant share of your exposure. Start by defining the systems and access types that matter to your organisation.

Your audit scope should cover:

  • Microsoft Entra ID user accounts, groups, administrative roles and privileged accounts
  • Microsoft Teams and Microsoft 365 Groups, including owners, members and guests
  • SharePoint sites, document libraries and folders with unique permissions or sharing links
  • Exchange Online shared mailboxes, mailbox delegation and distribution groups
  • External guest users, connected applications and consented third-party access
  • Intune roles, device administration rights and access to managed endpoints

The depth of review depends on your risk profile. A healthcare practice handling sensitive records may need more frequent and detailed reviews than a small construction business using Teams primarily for project coordination. Both still need clear ownership, a documented cadence and a process for acting on findings.

Prepare the audit before changing anything

Do not begin by removing access at random. That can interrupt payroll, project delivery or shared inbox workflows. First, nominate an audit owner and identify business owners for key systems. IT can report who has access, but department leaders are often best placed to confirm whether access remains necessary.

Create a simple audit register with the user or group name, system, level of access, business owner, justification, review date and action required. This turns a technical exercise into a record that management can review and approve.

It also helps to establish a baseline. Export current users, groups, roles and guests before making changes. If a staff member reports they have lost access later, you can identify what changed and restore only the appropriate permission.

How to audit Microsoft 365 permissions step by step

Start with privileged roles in Microsoft Entra ID

Administrative roles are the highest-priority review area because they can change settings, create accounts, access data or weaken security controls. Review global administrators first, then roles such as Exchange administrator, SharePoint administrator, Intune administrator, User administrator and Security administrator.

Check whether each assignment is active, still required and assigned to a named individual rather than a shared account. There should be very few global administrators. People who need elevated access only occasionally should not use a powerful account for email, web browsing or everyday work.

Where your Microsoft licensing and operating model support it, use time-limited privileged access rather than permanent assignments. This adds administration, but it reduces the window in which a stolen credential can cause major harm.

Review users, groups and ownership

Groups are efficient when managed well and dangerous when they are not. A single group can grant access to a Team, SharePoint site, mailbox or application. Review group membership alongside group ownership, because an owner can add members and alter settings.

Look for inactive accounts, duplicate groups, groups with no owner and groups with a vague purpose such as “Office Staff” or “Management”. If nobody can explain why a group exists or who approves membership, it should be investigated.

Where possible, allocate access through role-based groups rather than directly to individual users. For example, create a Finance Accounts Payable group instead of sharing folders one person at a time. This makes joiners, movers and leavers easier to manage, and gives the business a repeatable approval point.

Check Teams, SharePoint and sharing links

Teams and SharePoint are frequent sources of accidental oversharing. Review each active Team and sensitive SharePoint site for owners, members, guests and sharing settings. Pay particular attention to sites holding contracts, financial information, employee records, customer data or board documents.

Unique folder permissions deserve a closer look. They can be necessary for a confidential project, but they are difficult to track at scale. If a folder has been shared with individuals outside the normal group structure, confirm the reason and expiry date.

Review anonymous or anyone links carefully. They are convenient for sending a large file to a client, but they may be unsuitable for sensitive content. A safer option is often a named-user sharing link with a defined expiry. The right choice depends on the data classification, recipient and business need.

Remove or sponsor external access

Guest accounts are useful for clients, subcontractors and specialist advisers. They should not be treated like permanent staff accounts. Review the guest user list, identify the internal sponsor for each guest and confirm the engagement is still active.

Remove guests with no current purpose, especially those who have not signed in for an extended period. For remaining guests, check which Teams and sites they can access. A guest working on one project should not inherit access to unrelated company information through broad group membership.

Review mailbox and application access

Shared mailboxes can contain invoices, customer correspondence, employment information and commercial records. Confirm who has full access, send-as or send-on-behalf rights, and whether each permission is necessary. This is particularly important when staff move between finance, operations and management roles.

Also review enterprise applications and user consent. Third-party tools may retain access to mail, files, calendars or user profiles after a trial or project has ended. Remove unused applications and investigate permissions that are broader than the service appears to require.

Prioritise findings by risk, not by volume

A long list of permission changes is not automatically a useful audit outcome. Prioritise issues that create the greatest exposure or operational concern. A former global administrator is more urgent than an outdated member of a low-risk social Team.

High-priority findings usually include excessive administrative roles, disabled staff accounts that remain licensed or active, unowned groups, unmanaged guests, anonymous links to sensitive data, and shared mailboxes with unexplained delegation. Record the decision for each item, including who approved retention where access is kept.

This evidence matters. If an incident occurs, your organisation should be able to show that access was reviewed, exceptions were considered and corrective actions were completed. Plain-English reporting is valuable here: management needs to understand the risk, owner and due date without interpreting technical logs.

Make permission reviews part of normal operations

Permissions should be reviewed when staff join, change roles or leave, not only during an annual security exercise. Formal quarterly reviews are a sensible starting point for most organisations, with monthly checks for privileged roles, guests and high-risk systems. More frequent review may be needed where sensitive information, regulatory obligations or rapid workforce change are involved.

Automated alerts and access reviews can reduce manual effort, but automation does not replace business judgement. A system can identify an inactive guest account; it cannot reliably decide whether that consultant is about to begin the next project phase. Department ownership remains essential.

The strongest model combines documented onboarding and offboarding, group-based access, multifactor authentication, regular reporting and a clear escalation path for exceptions. It is proactive by default, rather than a scramble after a suspicious login or data-sharing mistake.

A permission audit is most effective when it becomes a routine management control, not a once-off tidy-up. Give each access decision an owner, a purpose and a review date. That discipline keeps Microsoft 365 useful for staff while making it much harder for unnecessary access to become an avoidable business risk.

← Back to all posts Book a free assessment