Microsoft 365 and Identity

Microsoft 365 is where most organisations now keep their mail, documents and identities, which makes the tenant one of the most valuable targets in the environment. It also tends to be administered informally, with licences assigned on request, permissions granted and never reviewed, and accounts left active long after somebody has left.

1

Assess

Tenant baseline

2

Secure

Identity controls first

3

Process

Joiner, mover, leaver

4

Govern

Sharing and retention

5

Report

Licences and posture

How We Manage It

01

Tenant Assessment

We baseline the tenant against a secure configuration and against what you are paying for. Unassigned licences, over licensed users and legacy authentication still enabled are the usual findings.

02

Identity and Access Security

Identity is the perimeter now. Multi factor authentication on every account, conditional access appropriate to your risk, and administrative privilege that is not held permanently by people who rarely need it.

03

Joiner, Mover and Leaver Process

This is where most access findings originate. A defined process means accounts are created with the right access, changed when people move, and disabled promptly when they leave rather than eventually.

04

Data Governance and Sharing

Sharing settings default to convenience. Left unreviewed, documents get shared externally with links that never expire, which is a POPIA exposure as much as a security one.

05

Ongoing Administration and Reporting

Routine administration handled, with monthly reporting on licence position, security posture and access changes so nothing drifts unnoticed between reviews.

What You Receive

Indicative Timeline

Assessment and hardening normally take three to five weeks. Enforcing multi factor authentication across all users is the step requiring the most communication, so it is phased rather than switched on overnight.

What We Manage

Tenant administration, identity security and the governance settings that determine where your data ends up.

Identity Security

Multi factor authentication, conditional access and privileged account control.

Licence Management

Assignment, reclamation and optimisation against what people actually use.

Joiner Mover Leaver

A defined process, which is the single most effective fix for recurring access findings.

External Sharing

Controls over what leaves the tenant and how long shared access persists.

Retention

Policies aligned to statutory retention and POPIA rather than left at default.

Backup

Microsoft 365 data backed up separately, since platform retention is not a backup.

Frequently Asked Questions

Not in the way people assume. The platform protects against its own infrastructure failure and offers limited retention. It does not protect against a user deleting a mailbox, a malicious insider or a retention policy expiring data you later need. Separate backup is warranted.

Yes. Attackers target whichever account lacks it, and an exempted executive is exactly the account they want. Where a genuine technical constraint exists we scope an alternative control rather than granting a permanent exemption.

As few as possible, usually two or three, with day to day work performed under lesser roles. Environments with a dozen global administrators are common and each one is a full compromise of the tenant if taken over.

Frequently. Unassigned licences, users on a higher tier than they need and accounts still licensed after departure are all common. Optimisation is reported monthly and typically pays for a meaningful part of the service.

Accounts should be disabled the same day, with mailbox access retained under a compliant arrangement where the business needs it. Leaver handling is the most frequent access finding we see and a defined process resolves it.

Not blocked, but controlled. Blocking it entirely drives people to personal accounts and consumer file sharing, which is worse. Expiry on links, review of shared content and sensitivity labelling are the proportionate response.

Related Services

This sits inside our Managed ICT Services practice. Related work: Backup and Disaster Recovery for the Microsoft 365 backup the platform does not provide, and POPIA Readiness for the retention and sharing obligations.

Discuss Microsoft 365 management