Microsoft 365 and Identity
Microsoft 365 is where most organisations now keep their mail, documents and identities, which makes the tenant one of the most valuable targets in the environment. It also tends to be administered informally, with licences assigned on request, permissions granted and never reviewed, and accounts left active long after somebody has left.
1
Assess
Tenant baseline
2
Secure
Identity controls first
3
Process
Joiner, mover, leaver
4
Govern
Sharing and retention
5
Report
Licences and posture
How We Manage It
01
Tenant Assessment
We baseline the tenant against a secure configuration and against what you are paying for. Unassigned licences, over licensed users and legacy authentication still enabled are the usual findings.
- Security configuration assessed against a secure baseline
- Licence position compared to actual usage
- Legacy authentication protocols identified
- Global administrator accounts enumerated and reviewed
02
Identity and Access Security
Identity is the perimeter now. Multi factor authentication on every account, conditional access appropriate to your risk, and administrative privilege that is not held permanently by people who rarely need it.
- Multi factor authentication enforced across all accounts
- Conditional access policies by risk, location and device
- Global administrator count reduced to a minimum
- Privileged access reviewed and time limited where supported
03
Joiner, Mover and Leaver Process
This is where most access findings originate. A defined process means accounts are created with the right access, changed when people move, and disabled promptly when they leave rather than eventually.
- Defined process with named owners at each step
- Standard access profiles by role
- Same day disablement on termination
- Periodic reconciliation of accounts against the HR register
04
Data Governance and Sharing
Sharing settings default to convenience. Left unreviewed, documents get shared externally with links that never expire, which is a POPIA exposure as much as a security one.
- External sharing settings reviewed and configured
- Link expiry and access review on shared content
- Sensitivity labelling where the data warrants it
- Retention and deletion policies aligned to obligations
05
Ongoing Administration and Reporting
Routine administration handled, with monthly reporting on licence position, security posture and access changes so nothing drifts unnoticed between reviews.
- Day to day tenant and licence administration
- Monthly security posture reporting
- Licence optimisation against actual usage
- Access change log reviewed periodically
What You Receive
- Tenant security baseline assessment with findings
- Multi factor authentication and conditional access configuration
- Documented joiner, mover and leaver process
- External sharing and retention policy configuration
- Licence optimisation with reclaimed licences identified
- Monthly reporting on posture, licences and access changes
Indicative Timeline
Assessment and hardening normally take three to five weeks. Enforcing multi factor authentication across all users is the step requiring the most communication, so it is phased rather than switched on overnight.
- Tenant assessment and baseline: one week
- Identity hardening and MFA rollout: two to three weeks
- Process definition and data governance: one week
- Ongoing administration with monthly reporting
What We Manage
Tenant administration, identity security and the governance settings that determine where your data ends up.
Identity Security
Multi factor authentication, conditional access and privileged account control.
Licence Management
Assignment, reclamation and optimisation against what people actually use.
Joiner Mover Leaver
A defined process, which is the single most effective fix for recurring access findings.
External Sharing
Controls over what leaves the tenant and how long shared access persists.
Retention
Policies aligned to statutory retention and POPIA rather than left at default.
Backup
Microsoft 365 data backed up separately, since platform retention is not a backup.
Frequently Asked Questions
Is Microsoft 365 data already backed up?
Not in the way people assume. The platform protects against its own infrastructure failure and offers limited retention. It does not protect against a user deleting a mailbox, a malicious insider or a retention policy expiring data you later need. Separate backup is warranted.
Do all users really need multi factor authentication?
Yes. Attackers target whichever account lacks it, and an exempted executive is exactly the account they want. Where a genuine technical constraint exists we scope an alternative control rather than granting a permanent exemption.
How many global administrators should we have?
As few as possible, usually two or three, with day to day work performed under lesser roles. Environments with a dozen global administrators are common and each one is a full compromise of the tenant if taken over.
Can you reduce our licence costs?
Frequently. Unassigned licences, users on a higher tier than they need and accounts still licensed after departure are all common. Optimisation is reported monthly and typically pays for a meaningful part of the service.
What about staff who have left?
Accounts should be disabled the same day, with mailbox access retained under a compliant arrangement where the business needs it. Leaver handling is the most frequent access finding we see and a defined process resolves it.
Does external sharing need to be locked down?
Not blocked, but controlled. Blocking it entirely drives people to personal accounts and consumer file sharing, which is worse. Expiry on links, review of shared content and sensitivity labelling are the proportionate response.
Related Services
This sits inside our Managed ICT Services practice. Related work: Backup and Disaster Recovery for the Microsoft 365 backup the platform does not provide, and POPIA Readiness for the retention and sharing obligations.
