Users
Every identity in the tenant - employees, guests, and the accounts nobody has signed into for a year - with what each one can reach, what it did, and whether it should still exist.
Users
The Users screen answers the question the rest of the platform is built around, from the identity's side: "What can this person reach, and what have they actually done with it?" Files, sites and groups describe the estate. Users describe who is standing in it.
What You Can Achieve
Answer 'what can this person reach?'
Every file, site, group and app one account can open - direct grants, group inheritance, sharing links and all. The question an auditor asks about a named employee, answered in one row.
Find guests nobody remembers inviting
External accounts split into Entra guests and SharePoint-only guests - the second kind never appears in your directory reports at all.
Catch dormant accounts holding access
Accounts with no sign-in and no activity for months, still carrying licenses, group memberships and reach into sensitive data.
Investigate before you offboard
See what a departing employee touched, what they still hold, and what breaks if you cut it - then run the offboarding automation from the same screen.
Internal, external, and the guests you can't see
Not every identity with access is an employee, and not every external identity is in your directory:
- Internal - accounts in your own tenant, licensed or not.
- Entra guests - external identities properly invited into the directory, visible in Microsoft's own reports.
- SharePoint-only guests - external people who got access through a sharing link or a site permission without ever becoming a directory object. They hold real access and are invisible to directory-based reviews - which is exactly why they accumulate.
Filter by any of these, and combine them with sensitivity and sharing filters to ask sharper questions: external users who can reach files containing sensitive information is two clicks.
Reading the list
Each row carries the identity's whole footprint, so you rarely need to open a drawer to triage:
| Column group | What it tells you |
|---|---|
| Reach | Groups, files and apps the account can reach - the size of what one compromised credential would open |
| Sensitive exposure | Sensitive information and labelled files within reach, plus the sharing links this user created |
| Activity | Last activity, last sign-in, an activity trend line, emails sent and received with their last timestamps |
| Account state | Account enabled, sign-in disabled, MFA registration, creation date, license assignment |
| Risk | Security alerts associated with the identity |
Sort by any of them. Files reachable descending is the fastest way to find the accounts worth reviewing first; last sign-in ascending is the fastest way to find the ones that should not exist.
Common investigations
- Offboarding audit - filter to a user, review reach and activity, then use Automations to revoke access, expire the links they created, and reclaim the license.
- Dormant with access - no sign-in for a year, still holding licenses and group memberships. Both a cost line and an attack path, see Activities.
- External exposure review - external users, filtered to those who can reach sensitive information - the report most access reviews are supposed to produce and rarely can.
- MFA gaps on privileged reach - accounts with wide reach and no registered MFA method.
- Incident scoping - start from the account named in an alert and read its activity, devices and locations from the Activity Logs.
Every user links straight into the permission graph - click through from a row to see why the access exists, path by path, rather than only that it does.
Agents
Govern every AI agent in your tenant - what each can actually read across files, sites, users, and email, who deployed it, and how to constrain it before rollout.
Files
Answer the question every access review stalls on - who has access to our files, and why - for every user, link, app, and AI agent across Microsoft 365.