Case Study
Untangling a Microsoft 365 tenant that grew without a plan
A professional services firm had accumulated ten years of Microsoft 365 configuration decisions. We reviewed identity, sharing and administrative access, and corrected the exposure without disrupting client work.
Client situation
A UK professional services firm with three offices and a long-standing outsourced IT provider. Microsoft 365 had been in place for around a decade, through two mergers and a hurried move to remote working.
The problem
Nobody could say with confidence who had access to client files, or how many people held administrative rights.
What we found
- Fourteen accounts held Global Administrator rights, including two belonging to former employees and one shared account used by the IT provider.
- Multi-factor authentication was enabled for most staff but excluded a group originally created for a 2020 migration, which still contained eleven active users.
- Over 3,000 anonymous sharing links had been created in SharePoint and OneDrive, the oldest dating from 2019, several pointing at folders containing client matter files.
- Mailbox auditing was enabled by default but log retention was too short to investigate anything older than 90 days.
- Two departed partners' mailboxes were still licensed, active, and receiving mail with no forwarding or review.
What we changed
- Reduced Global Administrator holders to two named accounts with just-in-time elevation, and moved the IT provider to a scoped delegated role.
- Removed the legacy MFA exclusion group, after a staged pilot with the eleven affected users to avoid a Monday-morning lockout.
- Audited and expired anonymous sharing links, then restricted new anonymous sharing to a narrow set of business cases with an expiry policy.
- Extended audit log retention and configured alerting on privileged role assignment and mailbox rule creation.
- Established a documented leaver process with the IT provider, covering licence reclamation, mailbox handling and access review.
Outcome
- The firm can now answer client and insurer questions about access control with evidence rather than assumption.
- Administrative access is minimal, named and logged, which materially reduces the impact of any single account compromise.
- The IT provider has a documented process to maintain, and has adopted the same leaver checklist for its other clients.
- A recurring six-monthly access review is now scheduled and owned by the operations director.
Why it mattered
The firm was not careless. Every one of these findings had a reasonable origin — a migration that needed an exclusion, a partner who left in a busy quarter, a client who could not receive a secure link and was sent an anonymous one instead.
The difficulty is that these decisions are individually small and collectively significant. No single person had visibility of all of them, and the support contract did not include anybody whose job was to look.
The part that took the longest
Not the technical work. Removing an MFA exclusion group takes minutes. Establishing which of the eleven users in it were genuinely active, what they used, and how to move them without stopping client work took the better part of a week — and that sequencing is precisely what makes the difference between a change that holds and one that gets reversed after the first complaint.
Relevant services
Make your technology safer — and more useful.
A short conversation is usually enough to establish whether there is something worth doing, and what it would involve. No obligation, and no sales script.